[PR #32224] docs(api): mark SetupApi as unauthenticated by design #33613

Closed
opened 2026-02-21 20:53:36 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/32224

State: closed
Merged: Yes


This endpoint is required for system initialization. During the initial bootstrap, no admin account exists yet; therefore, the frontend must be able to query setup progress before a login flow can be established.

ref: https://nvd.nist.gov/vuln/detail/CVE-2025-63386
Close: #32223

Summary

Screenshots

N/A

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran make lint and make type-check (backend) and cd web && npx lint-staged (frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/32224 **State:** closed **Merged:** Yes --- This endpoint is required for system initialization. During the initial bootstrap, no admin account exists yet; therefore, the frontend must be able to query setup progress before a login flow can be established. ref: https://nvd.nist.gov/vuln/detail/CVE-2025-63386 Close: #32223 ## Summary <!-- Please include a summary of the change and which issue is fixed. Please also include relevant motivation and context. List any dependencies that are required for this change. --> ## Screenshots N/A ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `make lint` and `make type-check` (backend) and `cd web && npx lint-staged` (frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:53:36 -05:00
yindo closed this issue 2026-02-21 20:53:36 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#33613