app_factory.py 5.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185
  1. import os
  2. from configs import dify_config
  3. if not dify_config.DEBUG:
  4. from gevent import monkey
  5. monkey.patch_all()
  6. import grpc.experimental.gevent
  7. grpc.experimental.gevent.init_gevent()
  8. import json
  9. from flask import Flask, Response, request
  10. from flask_cors import CORS
  11. from flask_login import user_loaded_from_request, user_logged_in
  12. from werkzeug.exceptions import Unauthorized
  13. import contexts
  14. from commands import register_commands
  15. from configs import dify_config
  16. from extensions import (
  17. ext_celery,
  18. ext_code_based_extension,
  19. ext_compress,
  20. ext_database,
  21. ext_hosting_provider,
  22. ext_logging,
  23. ext_login,
  24. ext_mail,
  25. ext_migrate,
  26. ext_proxy_fix,
  27. ext_redis,
  28. ext_sentry,
  29. ext_storage,
  30. )
  31. from extensions.ext_database import db
  32. from extensions.ext_login import login_manager
  33. from libs.passport import PassportService
  34. from services.account_service import AccountService
  35. class DifyApp(Flask):
  36. pass
  37. # ----------------------------
  38. # Application Factory Function
  39. # ----------------------------
  40. def create_flask_app_with_configs() -> Flask:
  41. """
  42. create a raw flask app
  43. with configs loaded from .env file
  44. """
  45. dify_app = DifyApp(__name__)
  46. dify_app.config.from_mapping(dify_config.model_dump())
  47. # populate configs into system environment variables
  48. for key, value in dify_app.config.items():
  49. if isinstance(value, str):
  50. os.environ[key] = value
  51. elif isinstance(value, int | float | bool):
  52. os.environ[key] = str(value)
  53. elif value is None:
  54. os.environ[key] = ""
  55. return dify_app
  56. def create_app() -> Flask:
  57. app = create_flask_app_with_configs()
  58. app.secret_key = dify_config.SECRET_KEY
  59. initialize_extensions(app)
  60. register_blueprints(app)
  61. register_commands(app)
  62. return app
  63. def initialize_extensions(app):
  64. # Since the application instance is now created, pass it to each Flask
  65. # extension instance to bind it to the Flask application instance (app)
  66. ext_logging.init_app(app)
  67. ext_compress.init_app(app)
  68. ext_code_based_extension.init()
  69. ext_database.init_app(app)
  70. ext_migrate.init(app, db)
  71. ext_redis.init_app(app)
  72. ext_storage.init_app(app)
  73. ext_celery.init_app(app)
  74. ext_login.init_app(app)
  75. ext_mail.init_app(app)
  76. ext_hosting_provider.init_app(app)
  77. ext_sentry.init_app(app)
  78. ext_proxy_fix.init_app(app)
  79. # Flask-Login configuration
  80. @login_manager.request_loader
  81. def load_user_from_request(request_from_flask_login):
  82. """Load user based on the request."""
  83. if request.blueprint not in {"console", "inner_api"}:
  84. return None
  85. # Check if the user_id contains a dot, indicating the old format
  86. auth_header = request.headers.get("Authorization", "")
  87. if not auth_header:
  88. auth_token = request.args.get("_token")
  89. if not auth_token:
  90. raise Unauthorized("Invalid Authorization token.")
  91. else:
  92. if " " not in auth_header:
  93. raise Unauthorized("Invalid Authorization header format. Expected 'Bearer <api-key>' format.")
  94. auth_scheme, auth_token = auth_header.split(None, 1)
  95. auth_scheme = auth_scheme.lower()
  96. if auth_scheme != "bearer":
  97. raise Unauthorized("Invalid Authorization header format. Expected 'Bearer <api-key>' format.")
  98. decoded = PassportService().verify(auth_token)
  99. user_id = decoded.get("user_id")
  100. logged_in_account = AccountService.load_logged_in_account(account_id=user_id)
  101. return logged_in_account
  102. @user_logged_in.connect
  103. @user_loaded_from_request.connect
  104. def on_user_logged_in(_sender, user):
  105. """Called when a user logged in."""
  106. if user:
  107. contexts.tenant_id.set(user.current_tenant_id)
  108. @login_manager.unauthorized_handler
  109. def unauthorized_handler():
  110. """Handle unauthorized requests."""
  111. return Response(
  112. json.dumps({"code": "unauthorized", "message": "Unauthorized."}),
  113. status=401,
  114. content_type="application/json",
  115. )
  116. # register blueprint routers
  117. def register_blueprints(app):
  118. from controllers.console import bp as console_app_bp
  119. from controllers.files import bp as files_bp
  120. from controllers.inner_api import bp as inner_api_bp
  121. from controllers.service_api import bp as service_api_bp
  122. from controllers.web import bp as web_bp
  123. CORS(
  124. service_api_bp,
  125. allow_headers=["Content-Type", "Authorization", "X-App-Code"],
  126. methods=["GET", "PUT", "POST", "DELETE", "OPTIONS", "PATCH"],
  127. )
  128. app.register_blueprint(service_api_bp)
  129. CORS(
  130. web_bp,
  131. resources={r"/*": {"origins": dify_config.WEB_API_CORS_ALLOW_ORIGINS}},
  132. supports_credentials=True,
  133. allow_headers=["Content-Type", "Authorization", "X-App-Code"],
  134. methods=["GET", "PUT", "POST", "DELETE", "OPTIONS", "PATCH"],
  135. expose_headers=["X-Version", "X-Env"],
  136. )
  137. app.register_blueprint(web_bp)
  138. CORS(
  139. console_app_bp,
  140. resources={r"/*": {"origins": dify_config.CONSOLE_CORS_ALLOW_ORIGINS}},
  141. supports_credentials=True,
  142. allow_headers=["Content-Type", "Authorization"],
  143. methods=["GET", "PUT", "POST", "DELETE", "OPTIONS", "PATCH"],
  144. expose_headers=["X-Version", "X-Env"],
  145. )
  146. app.register_blueprint(console_app_bp)
  147. CORS(files_bp, allow_headers=["Content-Type"], methods=["GET", "PUT", "POST", "DELETE", "OPTIONS", "PATCH"])
  148. app.register_blueprint(files_bp)
  149. app.register_blueprint(inner_api_bp)