Skip to content

fix(providers): validate Dify keys against native /v1/chat-messages endpoint (#11002) - #11065

Merged
diegosouzapw merged 1 commit into
release/v3.8.50from
fix/11002-dify-key-validation
Aug 21, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.50from
fix/11002-dify-key-validation

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Closes #11002

Root cause

The dify provider was registered with format: "openai" and baseUrl: "https://api.dify.ai/v1/chat/completions" in open-sse/config/providers/registry/dify/index.ts. Dify exposes no OpenAI-compatible HTTP API — its native completion endpoint is POST {base}/v1/chat-messages (body inputs/query/response_mode/user, returning 401 {"code":"unauthorized"} for a bad app key). There is no /v1/models listing.

So validateProviderApiKey dispatched through the generic OpenAI-like probe: GET /v1/models → 404, then POST /v1/chat/completions → 404, which openaiFormat.ts maps to "Provider validation endpoint not supported". Every real Dify app key failed the Check with that generic error instead of a clean invalid/valid verdict — and requests targeting /v1/chat/completions would also miss Dify's real route.

Fix

  • Added src/lib/providers/validation/dify.ts — a dedicated validateDifyProvider that probes POST {base}/v1/chat-messages (the Dify-native auth signal): 401/403 → Invalid API key, 2xx → valid, otherwise a generic validation failure. It honors providerSpecificData.baseUrl (for self-hosted instances) then falls back to the registry base URL, and always normalizes to {base}/v1/chat-messages (so a /v1 or full .../chat-messages override is also handled).
  • Registered it under dify: in the SPECIALTY_VALIDATORS map in src/lib/providers/validation.ts.
  • Changed the dify registry baseUrl to the bare API root https://api.dify.ai (without the /chat/completions suffix) so route suffixes build correctly.

Validation (Hard Rule #18 — TDD)

  • New regression test tests/unit/dify-key-validation-repro.test.ts starts a Dify-faithful local server (/v1/models → 404, /v1/chat/completions → 404, /v1/chat-messages → 401 for a bad key) and asserts validateProviderApiKey({provider:"dify", ...}) returns Invalid API key.
  • RED before the fix: AssertionError … expected 'Invalid API key', actual 'Provider validation endpoint not supported'. GREEN after (4/4 tests pass), plus unit coverage for difyValidationResultFromStatus, resolveDifyChatMessagesUrl, the registry baseUrl, and the dispatch registration.

Gates

  • typecheck:core: clean
  • eslint (changed files, suppressions applied): 0 errors
  • check-provider-consistency: OK
  • check-changelog-integrity: OK
  • file-size: no change to any of the touched files (only src/lib/modelCapabilities.ts fails, which this diff does not touch — pre-existing drift)

⚠️ base-red inherited: #9985

Note: I did not add an authHint field to the dify registry entry — RegistryEntry has no such schema field, so the per-app-key hint from the plan is out of scope for this bug fix.

@diegosouzapw
diegosouzapw merged commit 861ac69 into release/v3.8.50 Aug 21, 2026
15 of 22 checks passed
diegosouzapw pushed a commit that referenced this pull request Aug 22, 2026
…-web (#11000) (#11161)

Cherry-picked onto the current tip (authorship preserved), noise files stripped. Pre-merge addition: regenerated the golden snapshot with UPDATE_GOLDEN=1 because the branch's snapshot predated two legitimate tip changes — the dify bare-root from #11065 and the hackclub removal from #11123. The regen'd delta contains exactly those two (audited). This also drains a live base-red: provider-translate-path-golden was failing on the pure tip. 3/3 green. Thank you @rqzbeh!
@diegosouzapw
diegosouzapw deleted the fix/11002-dify-key-validation branch August 23, 2026 21:45
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…ndpoint (diegosouzapw#11002) (diegosouzapw#11065)

⭐5 — Fix do dono com TDD. Estado committed+pushed limpo (hold-vivo cedido por instrução direta do operador).
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…-web (diegosouzapw#11000) (diegosouzapw#11161)

Cherry-picked onto the current tip (authorship preserved), noise files stripped. Pre-merge addition: regenerated the golden snapshot with UPDATE_GOLDEN=1 because the branch's snapshot predated two legitimate tip changes — the dify bare-root from diegosouzapw#11065 and the hackclub removal from diegosouzapw#11123. The regen'd delta contains exactly those two (audited). This also drains a live base-red: provider-translate-path-golden was failing on the pure tip. 3/3 green. Thank you @rqzbeh!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(providers): dify key check always fails - validator probes /v1/chat/completions but Dify only serves /v1/chat-messages

2 participants