[PR #32334] Fix Marketplace HTTP Requests to Use SSRF Guard #33677

Open
opened 2026-02-21 20:53:42 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/32334

State: open
Merged: No


Important

  1. Make sure you have read our contribution guidelines
  2. Ensure there is an associated issue and you have been assigned to it
  3. Use the correct syntax to link this PR: Fixes #<issue number>.

Summary

This PR fixes a security vulnerability where HTTP requests in marketplace.py were bypassing the SSRF (Server-Side Request Forgery) protection guard. The record_install_plugin_event and fetch_global_plugin_manifest functions were making direct httpx calls instead of using the centralized ssrf_proxy guard.

Fix #32333

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran make lint and make type-check (backend) and cd web && npx lint-staged (frontend) to appease the lint gods

Testing

  • No linter errors introduced
  • All HTTP requests now go through SSRF guard
  • Existing functionality preserved (URL construction, headers, response handling, caching)
  • Code follows project conventions (docstrings, type annotations)

Files Changed

  • dify/api/core/helper/marketplace.py
    • Added ssrf_proxy import
    • Updated record_install_plugin_event() function
    • Updated fetch_global_plugin_manifest() function

Related Issue

Fixes #<issue_number>

**Original Pull Request:** https://github.com/langgenius/dify/pull/32334 **State:** open **Merged:** No --- > [!IMPORTANT] > > 1. Make sure you have read our [contribution guidelines](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) > 1. Ensure there is an associated issue and you have been assigned to it > 1. Use the correct syntax to link this PR: `Fixes #<issue number>`. ## Summary This PR fixes a security vulnerability where HTTP requests in `marketplace.py` were bypassing the SSRF (Server-Side Request Forgery) protection guard. The `record_install_plugin_event` and `fetch_global_plugin_manifest` functions were making direct `httpx` calls instead of using the centralized `ssrf_proxy` guard. Fix #32333 ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `make lint` and `make type-check` (backend) and `cd web && npx lint-staged` (frontend) to appease the lint gods ## Testing - ✅ No linter errors introduced - ✅ All HTTP requests now go through SSRF guard - ✅ Existing functionality preserved (URL construction, headers, response handling, caching) - ✅ Code follows project conventions (docstrings, type annotations) ## Files Changed - `dify/api/core/helper/marketplace.py` - Added `ssrf_proxy` import - Updated `record_install_plugin_event()` function - Updated `fetch_global_plugin_manifest()` function ## Related Issue Fixes #<issue_number>
yindo added the pull-request label 2026-02-21 20:53:42 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#33677