[PR #30697] fix(logstore): prevent SQL injection, fix serialization issues, and optimize initialization #32929

Closed
opened 2026-02-21 20:52:20 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/30697

State: closed
Merged: Yes


Important

  1. Make sure you have read our contribution guidelines
  2. Ensure there is an associated issue and you have been assigned to it
  3. Use the correct syntax to link this PR: Fixes #<issue number>.

Summary

This PR fixes critical security vulnerabilities, resolves workflow execution serialization issues, and optimizes the LogStore initialization process to improve system reliability.

Key Changes

1. Security: SQL Injection Prevention

  • Added SQL escape utilities to prevent SQL injection attacks and cross-tenant data access
  • Applied proper escaping for both SQL syntax and LogStore query syntax
  • Protects tenant_id, app_id, workflow_run_id and other identifiers from injection attacks

2. Serialization Fix

  • Fixed ArrayFileSegment type serialization issue in workflow execution
  • Now uses WorkflowRuntimeTypeConverter for proper serialization handling

3. Startup Optimization

  • Non-blocking Initialization: Perform a lightweight connectivity check to the configured logstore endpoint before establishing a full connection, to avoid blocking Dify's startup if the endpoint is unreachable.
  • Conditional Initialization: LogStore plugin initialization now only occurs when XXX_REPOSITORY is explicitly configured to use LogStore mode

4. Other Improvements

  • Connection Pool improvement : use SQLAlchemy connection pool for better connection recycling
  • Enhanced logging messages for better debugging
  • Improved some configuration comments

Screenshots

Before After
... ...

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran make lint and make type-check (backend) and cd web && npx lint-staged (frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/30697 **State:** closed **Merged:** Yes --- > [!IMPORTANT] > > 1. Make sure you have read our [contribution guidelines](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) > 1. Ensure there is an associated issue and you have been assigned to it > 1. Use the correct syntax to link this PR: `Fixes #<issue number>`. ## Summary This PR fixes critical security vulnerabilities, resolves workflow execution serialization issues, and optimizes the LogStore initialization process to improve system reliability. ### Key Changes #### 1. Security: SQL Injection Prevention - Added SQL escape utilities to prevent SQL injection attacks and cross-tenant data access - Applied proper escaping for both SQL syntax and LogStore query syntax - Protects tenant_id, app_id, workflow_run_id and other identifiers from injection attacks #### 2. Serialization Fix - Fixed `ArrayFileSegment` type serialization issue in workflow execution - Now uses `WorkflowRuntimeTypeConverter` for proper serialization handling #### 3. Startup Optimization - **Non-blocking Initialization:** Perform a lightweight connectivity check to the configured logstore endpoint before establishing a full connection, to avoid blocking Dify's startup if the endpoint is unreachable. - **Conditional Initialization**: LogStore plugin initialization now only occurs when `XXX_REPOSITORY` is explicitly configured to use LogStore mode #### 4. Other Improvements - Connection Pool improvement : use SQLAlchemy connection pool for better connection recycling - Enhanced logging messages for better debugging - Improved some configuration comments ## Screenshots | Before | After | |--------|-------| | ... | ... | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `make lint` and `make type-check` (backend) and `cd web && npx lint-staged` (frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:52:20 -05:00
yindo closed this issue 2026-02-21 20:52:20 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#32929