Skip to content

fix(invocation): preserve JSON in backwards requests - #828

Draft
WH-2099 wants to merge 1 commit into
mainfrom
fix/preserve-backwards-json
Draft

WH-2099 wants to merge 1 commit into
mainfrom
fix/preserve-backwards-json

Conversation

@WH-2099

@WH-2099 WH-2099 commented Sep 23, 2026

Copy link
Copy Markdown
Member

Description

Fixes #827.

Backwards LLM calls currently reject object-valued opaque_body before reaching Dify, while other JSON values can be corrupted ([49] becomes 1) and large integers are rounded.
Keep request values as json.RawMessage until typed dispatch, then use the JSON decoder with UseNumber and the existing validator.
This applies to all 17 backwards invocation types.

Preserve trusted tenant/user/type injection even when the incoming JSON uses case-folded aliases.
Accept null or omitted message content permitted by the SDK, including tool-only responses, while retaining validation of invalid content types.
The serverless missing-session error path now reads only the request ID, so unrelated large numbers cannot break error correlation.

Type of Change

  • Bug fix
  • New feature
  • Refactor
  • Performance improvement
  • Other

Essential Checklist

Testing

  • I have tested the changes locally and confirmed they work as expected
  • I have added unit tests where necessary and they pass successfully

Bug Fix (if applicable)

  • I have used GitHub syntax to close the related issue (e.g., Fixes #123 or Closes #123)

Additional Information

Validation passed:

go test -race ./internal/core/io_tunnel/backwards_invocation/... ./pkg/entities/model_entities
go vet ./internal/core/io_tunnel/backwards_invocation/... ./pkg/entities/model_entities

Tests start at InvokeDify with wire JSON and cover opaque objects/arrays/scalars, both stream flags, integers above 2^53, null/omitted content, all registered dispatch types, authorization, spoofed identity aliases, validation failures and end frames.
The serverless test exercises actual event parsing, typed LLM dispatch and its response writer with a controlled host implementation.
The regressions also fail against the original c798168 implementation through a Go source overlay.

Whole-repository checks were attempted with the CI test keys and a temporary Redis instance:

  • go test -timeout 1m ./cmd/... ./internal/... ./pkg/...: only internal/core/debugging_runtime failed because PostgreSQL was unavailable; the sandbox could not initialize a separate PostgreSQL data directory under its non-root service account.
  • go vet ./cmd/... ./internal/... ./pkg/...: reports the existing stopRenew context leak in unchanged internal/core/control_panel/launcher_local.go:92,127.

Temporary services were stopped, generated private keys removed and the original public key restored.
No paid model API was called.
Related context: #640 and langgenius/dify-official-plugins#3916.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(invocation): preserve opaque JSON and integer precision in backwards requests

1 participant