[PR #32380] fix: clear stale provider credentials during plugin uninstall #33703

Closed
opened 2026-02-21 20:53:44 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/32380

State: closed
Merged: Yes


Summary

This change hardens plugin uninstall credential cleanup to prevent stale provider state after plugin removal.

  • Removes the broad exception swallowing around cleanup in PluginService.uninstall.
  • Switches plugin uninstall cleanup to use an explicit SQLAlchemy Session transaction context.
  • Collects credentials by plugin-scoped provider namespace and removes all matching rows in bulk iteration.
  • Resets affected provider.credential_id values and clears the corresponding ProviderCredentialsCache entries.
  • Returns early to the plugin uninstall flow when target plugin is not found, keeping behavior unchanged.

Fixes #32378

Screenshots

Before After
Plugin uninstall could leave provider.credential_id pointing to non-existing records, causing inconsistent API responses. Plugin uninstall cleanup removes stale provider credential references and clears provider cache for affected records.

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran make lint and make type-check (backend) and cd web && npx lint-staged (frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/32380 **State:** closed **Merged:** Yes --- ## Summary This change hardens plugin uninstall credential cleanup to prevent stale provider state after plugin removal. - Removes the broad exception swallowing around cleanup in `PluginService.uninstall`. - Switches plugin uninstall cleanup to use an explicit SQLAlchemy `Session` transaction context. - Collects credentials by plugin-scoped provider namespace and removes all matching rows in bulk iteration. - Resets affected `provider.credential_id` values and clears the corresponding `ProviderCredentialsCache` entries. - Returns early to the plugin uninstall flow when target plugin is not found, keeping behavior unchanged. Fixes #32378 ## Screenshots | Before | After | |--------|-------| | Plugin uninstall could leave `provider.credential_id` pointing to non-existing records, causing inconsistent API responses. | Plugin uninstall cleanup removes stale provider credential references and clears provider cache for affected records. | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [ ] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [ ] I've updated the documentation accordingly. - [ ] I ran `make lint` and `make type-check` (backend) and `cd web && npx lint-staged` (frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:53:44 -05:00
yindo closed this issue 2026-02-21 20:53:44 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#33703