You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394
  1. from base64 import b64encode
  2. from functools import wraps
  3. from hashlib import sha1
  4. from hmac import new as hmac_new
  5. from flask import abort, request
  6. from configs import dify_config
  7. from extensions.ext_database import db
  8. from models.model import EndUser
  9. def billing_inner_api_only(view):
  10. @wraps(view)
  11. def decorated(*args, **kwargs):
  12. if not dify_config.INNER_API:
  13. abort(404)
  14. # get header 'X-Inner-Api-Key'
  15. inner_api_key = request.headers.get("X-Inner-Api-Key")
  16. if not inner_api_key or inner_api_key != dify_config.INNER_API_KEY:
  17. abort(401)
  18. return view(*args, **kwargs)
  19. return decorated
  20. def enterprise_inner_api_only(view):
  21. @wraps(view)
  22. def decorated(*args, **kwargs):
  23. if not dify_config.INNER_API:
  24. abort(404)
  25. # get header 'X-Inner-Api-Key'
  26. inner_api_key = request.headers.get("X-Inner-Api-Key")
  27. if not inner_api_key or inner_api_key != dify_config.INNER_API_KEY:
  28. abort(401)
  29. return view(*args, **kwargs)
  30. return decorated
  31. def enterprise_inner_api_user_auth(view):
  32. @wraps(view)
  33. def decorated(*args, **kwargs):
  34. if not dify_config.INNER_API:
  35. return view(*args, **kwargs)
  36. # get header 'X-Inner-Api-Key'
  37. authorization = request.headers.get("Authorization")
  38. if not authorization:
  39. return view(*args, **kwargs)
  40. parts = authorization.split(":")
  41. if len(parts) != 2:
  42. return view(*args, **kwargs)
  43. user_id, token = parts
  44. if " " in user_id:
  45. user_id = user_id.split(" ")[1]
  46. inner_api_key = request.headers.get("X-Inner-Api-Key", "")
  47. data_to_sign = f"DIFY {user_id}"
  48. signature = hmac_new(inner_api_key.encode("utf-8"), data_to_sign.encode("utf-8"), sha1)
  49. signature_base64 = b64encode(signature.digest()).decode("utf-8")
  50. if signature_base64 != token:
  51. return view(*args, **kwargs)
  52. kwargs["user"] = db.session.query(EndUser).where(EndUser.id == user_id).first()
  53. return view(*args, **kwargs)
  54. return decorated
  55. def plugin_inner_api_only(view):
  56. @wraps(view)
  57. def decorated(*args, **kwargs):
  58. if not dify_config.PLUGIN_DAEMON_KEY:
  59. abort(404)
  60. # get header 'X-Inner-Api-Key'
  61. inner_api_key = request.headers.get("X-Inner-Api-Key")
  62. if not inner_api_key or inner_api_key != dify_config.INNER_API_KEY_FOR_PLUGIN:
  63. abort(404)
  64. return view(*args, **kwargs)
  65. return decorated