fix(web): correct MCP forward-identity header copy; guard toggle hydration (#37176)

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Charles Yao
2026-06-12 01:45:51 +00:00
committed by GitHub
co-authored by Claude Opus 4.8
parent b61d39ae2b
commit aff8f82bc0
27 changed files with 72 additions and 28 deletions
+3 -3
View File
@@ -30,7 +30,7 @@ logger = logging.getLogger(__name__)
# Custom header used to carry the forwarded SSO access token. Picked to avoid
# stomping on the workspace-scoped Authorization header (provider OAuth /
# user-supplied custom credentials), which would silently break those flows.
FORWARDED_IDENTITY_HEADER = "X-Dify-SSO-Access-Token"
FORWARDED_IDENTITY_HEADER = "X-Dify-SSO-Token"
class MCPTool(Tool):
@@ -305,7 +305,7 @@ class MCPTool(Tool):
# Forwarded identity rides in a custom header so workspace-scoped
# provider credentials (Authorization / custom Headers) keep working
# untouched. The MCP server is expected to read X-Dify-SSO-Access-Token
# untouched. The MCP server is expected to read X-Dify-SSO-Token
# when identity forwarding is configured.
forward_identity_active = False
if self._forwarding_requested and user_id:
@@ -338,7 +338,7 @@ class MCPTool(Tool):
audience: str,
) -> None:
"""Call the enterprise IssueMCPToken endpoint and stamp the issued
token into X-Dify-SSO-Access-Token.
token into X-Dify-SSO-Token.
A custom header is used (rather than Authorization) so it composes
with workspace-scoped provider credentials — the user may have OAuth
@@ -141,7 +141,7 @@ class EnterpriseService:
the calling Dify user, audience-scoped to the given MCP server identifier.
Used by MCPTool.invoke_remote_mcp_tool to stamp the
X-Dify-SSO-Access-Token header on outbound MCP requests when the
X-Dify-SSO-Token header on outbound MCP requests when the
provider's identity_mode is set to "idp_token".
Returns:
@@ -177,7 +177,7 @@ def _build_forwarding_tool(*, mode: str = "idp_token") -> MCPTool:
def test_inject_forwarded_identity_stamps_custom_header():
"""The minted SSO token must be placed in X-Dify-SSO-Access-Token; the
"""The minted SSO token must be placed in X-Dify-SSO-Token; the
workspace-scoped Authorization header and any other custom headers must
pass through untouched so provider credentials keep working."""
from core.tools.mcp_tool.tool import FORWARDED_IDENTITY_HEADER