mirror of
https://github.com/langgenius/dify.git
synced 2026-09-24 23:22:26 +08:00
fix(web): correct MCP forward-identity header copy; guard toggle hydration (#37176)
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
b61d39ae2b
commit
aff8f82bc0
@@ -30,7 +30,7 @@ logger = logging.getLogger(__name__)
|
||||
# Custom header used to carry the forwarded SSO access token. Picked to avoid
|
||||
# stomping on the workspace-scoped Authorization header (provider OAuth /
|
||||
# user-supplied custom credentials), which would silently break those flows.
|
||||
FORWARDED_IDENTITY_HEADER = "X-Dify-SSO-Access-Token"
|
||||
FORWARDED_IDENTITY_HEADER = "X-Dify-SSO-Token"
|
||||
|
||||
|
||||
class MCPTool(Tool):
|
||||
@@ -305,7 +305,7 @@ class MCPTool(Tool):
|
||||
|
||||
# Forwarded identity rides in a custom header so workspace-scoped
|
||||
# provider credentials (Authorization / custom Headers) keep working
|
||||
# untouched. The MCP server is expected to read X-Dify-SSO-Access-Token
|
||||
# untouched. The MCP server is expected to read X-Dify-SSO-Token
|
||||
# when identity forwarding is configured.
|
||||
forward_identity_active = False
|
||||
if self._forwarding_requested and user_id:
|
||||
@@ -338,7 +338,7 @@ class MCPTool(Tool):
|
||||
audience: str,
|
||||
) -> None:
|
||||
"""Call the enterprise IssueMCPToken endpoint and stamp the issued
|
||||
token into X-Dify-SSO-Access-Token.
|
||||
token into X-Dify-SSO-Token.
|
||||
|
||||
A custom header is used (rather than Authorization) so it composes
|
||||
with workspace-scoped provider credentials — the user may have OAuth
|
||||
|
||||
@@ -141,7 +141,7 @@ class EnterpriseService:
|
||||
the calling Dify user, audience-scoped to the given MCP server identifier.
|
||||
|
||||
Used by MCPTool.invoke_remote_mcp_tool to stamp the
|
||||
X-Dify-SSO-Access-Token header on outbound MCP requests when the
|
||||
X-Dify-SSO-Token header on outbound MCP requests when the
|
||||
provider's identity_mode is set to "idp_token".
|
||||
|
||||
Returns:
|
||||
|
||||
@@ -177,7 +177,7 @@ def _build_forwarding_tool(*, mode: str = "idp_token") -> MCPTool:
|
||||
|
||||
|
||||
def test_inject_forwarded_identity_stamps_custom_header():
|
||||
"""The minted SSO token must be placed in X-Dify-SSO-Access-Token; the
|
||||
"""The minted SSO token must be placed in X-Dify-SSO-Token; the
|
||||
workspace-scoped Authorization header and any other custom headers must
|
||||
pass through untouched so provider credentials keep working."""
|
||||
from core.tools.mcp_tool.tool import FORWARDED_IDENTITY_HEADER
|
||||
|
||||
Reference in New Issue
Block a user