setup_endpoint.go 8.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251
  1. package service
  2. import (
  3. "fmt"
  4. "github.com/langgenius/dify-plugin-daemon/internal/core/dify_invocation"
  5. "github.com/langgenius/dify-plugin-daemon/internal/core/plugin_manager"
  6. "github.com/langgenius/dify-plugin-daemon/internal/db"
  7. "github.com/langgenius/dify-plugin-daemon/internal/service/install_service"
  8. "github.com/langgenius/dify-plugin-daemon/internal/types/entities"
  9. "github.com/langgenius/dify-plugin-daemon/internal/types/entities/plugin_entities"
  10. "github.com/langgenius/dify-plugin-daemon/internal/types/models"
  11. "github.com/langgenius/dify-plugin-daemon/internal/utils/encryption"
  12. )
  13. func SetupEndpoint(
  14. tenant_id string,
  15. user_id string,
  16. plugin_unique_identifier plugin_entities.PluginUniqueIdentifier,
  17. settings map[string]any,
  18. ) *entities.Response {
  19. // try find plugin installation
  20. installation, err := db.GetOne[models.PluginInstallation](
  21. db.Equal("tenant_id", tenant_id),
  22. db.Equal("plugin_unique_identifier", plugin_unique_identifier.String()),
  23. )
  24. if err != nil {
  25. return entities.NewErrorResponse(-404, fmt.Sprintf("failed to find plugin installation: %v", err))
  26. }
  27. // try get plugin
  28. plugin, err := db.GetOne[models.Plugin](
  29. db.Equal("plugin_unique_identifier", plugin_unique_identifier.String()),
  30. )
  31. if err != nil {
  32. return entities.NewErrorResponse(-404, fmt.Sprintf("failed to find plugin: %v", err))
  33. }
  34. declaration := plugin.Declaration
  35. if !declaration.Resource.Permission.AllowRegisterEndpoint() {
  36. return entities.NewErrorResponse(-403, "permission denied")
  37. }
  38. if declaration.Endpoint == nil {
  39. return entities.NewErrorResponse(-404, "plugin does not have an endpoint")
  40. }
  41. // check settings
  42. if err := plugin_entities.ValidateProviderConfigs(settings, declaration.Endpoint.Settings); err != nil {
  43. return entities.NewErrorResponse(-400, fmt.Sprintf("failed to validate settings: %v", err))
  44. }
  45. endpoint, err := install_service.InstallEndpoint(
  46. plugin_unique_identifier,
  47. installation.ID,
  48. tenant_id,
  49. user_id,
  50. map[string]any{},
  51. )
  52. if err != nil {
  53. return entities.NewErrorResponse(-500, fmt.Sprintf("failed to setup endpoint: %v", err))
  54. }
  55. manager := plugin_manager.Manager()
  56. if manager == nil {
  57. return entities.NewErrorResponse(-500, "failed to get plugin manager")
  58. }
  59. // encrypt settings
  60. encrypted_settings, err := manager.BackwardsInvocation().InvokeEncrypt(
  61. &dify_invocation.InvokeEncryptRequest{
  62. BaseInvokeDifyRequest: dify_invocation.BaseInvokeDifyRequest{
  63. TenantId: tenant_id,
  64. UserId: user_id,
  65. Type: dify_invocation.INVOKE_TYPE_ENCRYPT,
  66. },
  67. InvokeEncryptSchema: dify_invocation.InvokeEncryptSchema{
  68. Opt: dify_invocation.ENCRYPT_OPT_ENCRYPT,
  69. Namespace: dify_invocation.ENCRYPT_NAMESPACE_ENDPOINT,
  70. Identity: endpoint.ID,
  71. Data: settings,
  72. Config: declaration.Endpoint.Settings,
  73. },
  74. },
  75. )
  76. if err != nil {
  77. return entities.NewErrorResponse(-500, fmt.Sprintf("failed to encrypt settings: %v", err))
  78. }
  79. if err := install_service.UpdateEndpoint(endpoint, encrypted_settings); err != nil {
  80. return entities.NewErrorResponse(-500, fmt.Sprintf("failed to update endpoint: %v", err))
  81. }
  82. return entities.NewSuccessResponse(nil)
  83. }
  84. func RemoveEndpoint(endpoint_id string, tenant_id string) *entities.Response {
  85. endpoint, err := db.GetOne[models.Endpoint](
  86. db.Equal("endpoint_id", endpoint_id),
  87. db.Equal("tenant_id", tenant_id),
  88. )
  89. if err != nil {
  90. return entities.NewErrorResponse(-404, fmt.Sprintf("failed to find endpoint: %v", err))
  91. }
  92. err = install_service.UninstallEndpoint(&endpoint)
  93. if err != nil {
  94. return entities.NewErrorResponse(-500, fmt.Sprintf("failed to remove endpoint: %v", err))
  95. }
  96. manager := plugin_manager.Manager()
  97. if manager == nil {
  98. return entities.NewErrorResponse(-500, "failed to get plugin manager")
  99. }
  100. // clear credentials cache
  101. if _, err := manager.BackwardsInvocation().InvokeEncrypt(&dify_invocation.InvokeEncryptRequest{
  102. BaseInvokeDifyRequest: dify_invocation.BaseInvokeDifyRequest{
  103. TenantId: tenant_id,
  104. UserId: "",
  105. Type: dify_invocation.INVOKE_TYPE_ENCRYPT,
  106. },
  107. InvokeEncryptSchema: dify_invocation.InvokeEncryptSchema{
  108. Opt: dify_invocation.ENCRYPT_OPT_CLEAR,
  109. Namespace: dify_invocation.ENCRYPT_NAMESPACE_ENDPOINT,
  110. Identity: endpoint.ID,
  111. },
  112. }); err != nil {
  113. return entities.NewErrorResponse(-500, fmt.Sprintf("failed to clear credentials cache: %v", err))
  114. }
  115. return entities.NewSuccessResponse(nil)
  116. }
  117. func UpdateEndpoint(endpoint_id string, tenant_id string, user_id string, settings map[string]any) *entities.Response {
  118. // get endpoint
  119. endpoint, err := db.GetOne[models.Endpoint](
  120. db.Equal("id", endpoint_id),
  121. db.Equal("tenant_id", tenant_id),
  122. )
  123. if err != nil {
  124. return entities.NewErrorResponse(-404, fmt.Sprintf("failed to find endpoint: %v", err))
  125. }
  126. // get plugin installation
  127. installation, err := db.GetOne[models.PluginInstallation](
  128. db.Equal("plugin_id", endpoint.PluginID),
  129. db.Equal("tenant_id", tenant_id),
  130. )
  131. if err != nil {
  132. return entities.NewErrorResponse(-404, fmt.Sprintf("failed to find plugin installation: %v", err))
  133. }
  134. // get plugin
  135. plugin, err := db.GetOne[models.Plugin](
  136. db.Equal("plugin_unique_identifier", installation.PluginUniqueIdentifier),
  137. )
  138. if err != nil {
  139. return entities.NewErrorResponse(-404, fmt.Sprintf("failed to find plugin: %v", err))
  140. }
  141. if plugin.Declaration.Endpoint == nil {
  142. return entities.NewErrorResponse(-404, "plugin does not have an endpoint")
  143. }
  144. // decrypt original settings
  145. manager := plugin_manager.Manager()
  146. if manager == nil {
  147. return entities.NewErrorResponse(-500, "failed to get plugin manager")
  148. }
  149. original_settings, err := manager.BackwardsInvocation().InvokeEncrypt(
  150. &dify_invocation.InvokeEncryptRequest{
  151. BaseInvokeDifyRequest: dify_invocation.BaseInvokeDifyRequest{
  152. TenantId: tenant_id,
  153. UserId: user_id,
  154. Type: dify_invocation.INVOKE_TYPE_ENCRYPT,
  155. },
  156. InvokeEncryptSchema: dify_invocation.InvokeEncryptSchema{
  157. Opt: dify_invocation.ENCRYPT_OPT_DECRYPT,
  158. Namespace: dify_invocation.ENCRYPT_NAMESPACE_ENDPOINT,
  159. Identity: installation.ID,
  160. Data: endpoint.GetSettings(),
  161. Config: plugin.Declaration.Endpoint.Settings,
  162. },
  163. },
  164. )
  165. if err != nil {
  166. return entities.NewErrorResponse(-500, fmt.Sprintf("failed to decrypt settings: %v", err))
  167. }
  168. masked_settings := encryption.MaskConfigCredentials(original_settings, plugin.Declaration.Endpoint.Settings)
  169. // check if settings is changed, replace the value is the same as masked_settings
  170. for setting_name, value := range settings {
  171. if masked_settings[setting_name] != value {
  172. settings[setting_name] = original_settings[setting_name]
  173. }
  174. }
  175. // check settings
  176. if err := plugin_entities.ValidateProviderConfigs(settings, plugin.Declaration.Endpoint.Settings); err != nil {
  177. return entities.NewErrorResponse(-400, fmt.Sprintf("failed to validate settings: %v", err))
  178. }
  179. // encrypt settings
  180. encrypted_settings, err := manager.BackwardsInvocation().InvokeEncrypt(
  181. &dify_invocation.InvokeEncryptRequest{
  182. BaseInvokeDifyRequest: dify_invocation.BaseInvokeDifyRequest{
  183. TenantId: tenant_id,
  184. UserId: user_id,
  185. Type: dify_invocation.INVOKE_TYPE_ENCRYPT,
  186. },
  187. InvokeEncryptSchema: dify_invocation.InvokeEncryptSchema{
  188. Opt: dify_invocation.ENCRYPT_OPT_ENCRYPT,
  189. Namespace: dify_invocation.ENCRYPT_NAMESPACE_ENDPOINT,
  190. Identity: endpoint.ID,
  191. Data: settings,
  192. Config: plugin.Declaration.Endpoint.Settings,
  193. },
  194. },
  195. )
  196. if err != nil {
  197. return entities.NewErrorResponse(-500, fmt.Sprintf("failed to encrypt settings: %v", err))
  198. }
  199. // update endpoint
  200. if err := install_service.UpdateEndpoint(&endpoint, encrypted_settings); err != nil {
  201. return entities.NewErrorResponse(-500, fmt.Sprintf("failed to update endpoint: %v", err))
  202. }
  203. // clear credentials cache
  204. if _, err := manager.BackwardsInvocation().InvokeEncrypt(&dify_invocation.InvokeEncryptRequest{
  205. BaseInvokeDifyRequest: dify_invocation.BaseInvokeDifyRequest{
  206. TenantId: tenant_id,
  207. UserId: user_id,
  208. Type: dify_invocation.INVOKE_TYPE_ENCRYPT,
  209. },
  210. InvokeEncryptSchema: dify_invocation.InvokeEncryptSchema{
  211. Opt: dify_invocation.ENCRYPT_OPT_CLEAR,
  212. Namespace: dify_invocation.ENCRYPT_NAMESPACE_ENDPOINT,
  213. Identity: endpoint.ID,
  214. },
  215. }); err != nil {
  216. return entities.NewErrorResponse(-500, fmt.Sprintf("failed to clear credentials cache: %v", err))
  217. }
  218. return entities.NewSuccessResponse(nil)
  219. }