Repository navigation
fix(providers): validate Dify keys against native /v1/chat-messages endpoint (#11002) - #11065
Merged
Merged
Conversation
diegosouzapw
pushed a commit
that referenced
this pull request
Aug 22, 2026
…-web (#11000) (#11161) Cherry-picked onto the current tip (authorship preserved), noise files stripped. Pre-merge addition: regenerated the golden snapshot with UPDATE_GOLDEN=1 because the branch's snapshot predated two legitimate tip changes — the dify bare-root from #11065 and the hackclub removal from #11123. The regen'd delta contains exactly those two (audited). This also drains a live base-red: provider-translate-path-golden was failing on the pure tip. 3/3 green. Thank you @rqzbeh!
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…ndpoint (diegosouzapw#11002) (diegosouzapw#11065) ⭐5 — Fix do dono com TDD. Estado committed+pushed limpo (hold-vivo cedido por instrução direta do operador).
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…-web (diegosouzapw#11000) (diegosouzapw#11161) Cherry-picked onto the current tip (authorship preserved), noise files stripped. Pre-merge addition: regenerated the golden snapshot with UPDATE_GOLDEN=1 because the branch's snapshot predated two legitimate tip changes — the dify bare-root from diegosouzapw#11065 and the hackclub removal from diegosouzapw#11123. The regen'd delta contains exactly those two (audited). This also drains a live base-red: provider-translate-path-golden was failing on the pure tip. 3/3 green. Thank you @rqzbeh!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #11002
Root cause
The
difyprovider was registered withformat: "openai"andbaseUrl: "https://api.dify.ai/v1/chat/completions"inopen-sse/config/providers/registry/dify/index.ts. Dify exposes no OpenAI-compatible HTTP API — its native completion endpoint isPOST {base}/v1/chat-messages(bodyinputs/query/response_mode/user, returning401 {"code":"unauthorized"}for a bad app key). There is no/v1/modelslisting.So
validateProviderApiKeydispatched through the generic OpenAI-like probe:GET /v1/models→ 404, thenPOST /v1/chat/completions→ 404, whichopenaiFormat.tsmaps to"Provider validation endpoint not supported". Every real Dify app key failed the Check with that generic error instead of a clean invalid/valid verdict — and requests targeting/v1/chat/completionswould also miss Dify's real route.Fix
src/lib/providers/validation/dify.ts— a dedicatedvalidateDifyProviderthat probesPOST {base}/v1/chat-messages(the Dify-native auth signal): 401/403 →Invalid API key, 2xx → valid, otherwise a generic validation failure. It honorsproviderSpecificData.baseUrl(for self-hosted instances) then falls back to the registry base URL, and always normalizes to{base}/v1/chat-messages(so a/v1or full.../chat-messagesoverride is also handled).dify:in theSPECIALTY_VALIDATORSmap insrc/lib/providers/validation.ts.baseUrlto the bare API roothttps://api.dify.ai(without the/chat/completionssuffix) so route suffixes build correctly.Validation (Hard Rule #18 — TDD)
tests/unit/dify-key-validation-repro.test.tsstarts a Dify-faithful local server (/v1/models→ 404,/v1/chat/completions→ 404,/v1/chat-messages→ 401 for a bad key) and assertsvalidateProviderApiKey({provider:"dify", ...})returnsInvalid API key.AssertionError … expected 'Invalid API key', actual 'Provider validation endpoint not supported'. GREEN after (4/4 tests pass), plus unit coverage fordifyValidationResultFromStatus,resolveDifyChatMessagesUrl, the registry baseUrl, and the dispatch registration.Gates
src/lib/modelCapabilities.tsfails, which this diff does not touch — pre-existing drift)Note: I did not add an
authHintfield to the dify registry entry —RegistryEntryhas no such schema field, so the per-app-key hint from the plan is out of scope for this bug fix.