## langgenius/dify — 1.16.1…1.17.0

_820+ commits._

### Features
- **feat: hide add library skill in agent ui (#41250)** (a6fe278)
- **feat(api): track credit usage contexts (#41181)** (9600182)
- **feat: add skill enable feature switch (#41246)** (ddcdbb2)
- **feat(api): support New Agent Beta for inline Workflow agents (#41215)** (1afac21)
- **feat(web): enhance Go to Anything navigation and discovery (#41160)** (21d540f)
- **feat: support agent skill (#39675)** (0024a84)
- **feat(trace): add provider-neutral unified tracing (#39451)** (3a8fbcb)
- **feat: Enterprise Home Snapshot — runtime endpoints and dify-agent adapter (#40996)** (d614745)
- **feat: support ODT document extraction (#39973)** (ccfb47d)

### Fixes
- **fix(ui): add tabs panel focus treatment (#41231)** (9ce92d8)
- **fix: show a not-allowed cursor for the prompt editor in build mode (#41243)** (18d3990)
- **fix(skills): align Japanese Skills page title (#41242)** (03e4bc5)
- **fix: prevent sidebar footer actions from triggering hover preview (#41230)** (370efc4)
- **fix(api): enforce APP_EDIT RBAC permission on MCP server refresh endpoint (#41235)** (cf236ae)
- **fix: fix skill display name rename conflict (#41229)** (bc845ea)
- **fix(cli): declare write effect for import and context-switch commands (#41225)** (dd2e691)
- **fix: allow OAuth trigger builder verification without credentials (#39199)** (f360a7b)
- **fix(web): stop digits rendering in the emoji font (#41201)** (1e501cd)
- **fix(docker): harden agent compose configuration (#41065)** (45cb385)
- **perf(agent): exponential backoff in polling to prevent forking storm (#41222)** (679514d)
- **perf(agent): polling interval tuning (#41221)** (9643dca)
- **fix: enforce read-only agent resources in build mode (#41220)** (fcb3800)
- **perf(api): batch recommended app catalog lookups (#41218)** (d4ed92c)
- **fix: address Agent UX feedback (#41219)** (12f259e)
- **fix(types): replace any[] with ThoughtItem[] for agent_thoughts (#41141)** (d9ca69d)
- **fix(model): re-sign bare/backticked tool file URLs in answer (#40799)** (ebb0f12)
- **fix(skills): align management UI accessibility and localization (#41180)** (667d66c)
- **fix(web): refresh model provider version after update (#41212)** (b56d30b)
- **fix(web): restore model selector popup spacing (#41190)** (8d61289)
- **fix: failed e2e test in agent caused by changed copywriting (#41187)** (e25ca61)
- **fix: avoid copy-sensitive agent file toast assertion (#41179)** (44aec25)
- **fix: refine agent configuration copy (#41177)** (2be3c3d)
- **fix: keep pagination skeletons in app grid (#41175)** (09b199b)
- **fix(api): attach exc_info=True to 11 logger.debug/info('...: %s', str(e)) sites — sibling of #41066 (DEBUG/INFO level) (#41077)** (ff3cf56)
- **fix: align main navigation card grids (#41167)** (b598292)
- **fix(api): respect configured model params in prompt generator (#41165)** (28a4859)
- **fix: preserve agent task editor focus when inserting commands (#41166)** (fef2809)
- **fix: keep home intro without banner (#41155)** (3de20e0)
- **fix(web): align agent v2 monitoring translations (#41161)** (703f6d1)
- **fix(agent): allow saving model-less inline Agent drafts (#41147)** (4847447)
- **fix: align duplicate agent name behavior with agent forms (#41156)** (7cb9aa2)
- **fix(web): align agent v2 monitoring copy (#41150)** (3ab8476)
- **fix: show checklist errors for inline agents without models (#41146)** (693e1b0)
- **fix(api): scope hosted credits by tenant plan (#41131)** (70a513f)
- **fix: fix upload for plugin (#41133)** (bec4ef6)
- **fix: stabilize the agent tool picker placement (#41132)** (24287bc)
- **fix(tts): propagate and validate actual audio MIME (#41043)** (3f7e6cd)
- **fix: fall back to the batch API when the global plugin manifest is empty (#41107)** (ea6c15b)
- **fix(workflow): honor stop between non-streaming nodes (#41090)** (ab34f9a)
- **fix(agent): avoid empty Bedrock schema fields (#40443)** (9385e58)
- **fix(agent-v2): prevent workflow refresh render loop (#41105)** (8bdf702)
- **fix(api): enforce admin and RBAC permissions on default model and provider models GET endpoints (#41099) (#41100)** (24f5e2a)
- **fix(api): enforce admin and RBAC permissions on data source integrates GET endpoint (#41079) (#41080)** (07119e3)
- **fix(api): attach exc_info=True to logger.warning sites that drop the traceback (#41068)** (23150c2)
- **fix(web): prevent signin page content from overflowing on mobile (#40921)** (7d5c68c)
- **fix(vdb): add document_id keyword mapping and fix VectorType in elasticsearch-ja adapter (#40400)** (385e866)
- **fix: add missing metrics back and enhance typing (#40935)** (373f33f)
- **fix(web): prevent Safari clipping tour recovery prompt (#41060)** (faca558)
- **fix: merge system messages and place them first to comply with Qwen/v… (#39136)** (34fdac2)
- **Fix dropped workflow events in Redis** — Fixed a race condition where workflow_started events could be lost in Redis Streams when clients subscribe slightly after an event is published. The fix prepares subscription delivery boundaries before activation, ensuring no events are missed even with timing gaps. (9d8dacd)
- **Restrict endpoint listings to admins** — Added permission checks to endpoint listing endpoints to ensure only workspace admins or owners with plugin configuration permissions can access them. Both the general endpoint list and single-plugin endpoint list APIs now require proper authorization. (a5e284e)
- **Fix enterprise documentation links** — Documentation links now properly route to enterprise documentation when deployed on the Enterprise edition. The system now accepts a configurable documentation URL from the provider instead of hardcoding the public docs URL, allowing different deployments to point to their own documentation. (3d08b2f)
- **Secure datasource credential retrieval** — Added permission checks to the datasource credential GET endpoint to enforce edit permissions and role-based access control (RBAC), matching the security requirements of the POST endpoint. Users must now have the appropriate dataset credential management permissions to view datasource credentials. (43e59d3)
- **Strengthen app access control checks** — The system now enforces stricter permission validation when users access workflows and import app configurations. It checks whether users have proper access rights to apps they're trying to view or modify, especially when role-based access control (RBAC) is enabled, preventing unauthorized access to indirect resources. (edc805c)
- **Configure binding file upload timeouts** — Added configurable timeout settings for binding file uploads across the agent backend and runtime. The API now supports a 240-second default timeout for converting binding files to tool files, while the agent runtime uses a 180-second HTTP client timeout and 210-second command timeout for the same operation. (0ca9931)
- **Skip permission check when RBAC enabled** — Fixed dataset permission validation to only run when RBAC (role-based access control) is disabled. When RBAC is enabled, the system now relies on RBAC's own permission checks instead of the dataset-specific permission check. (785ca4b)
- **fix: add MESSAGE_TRACE task on chat pipline error events (#39129)** (e425e18)
- **fix(api): add missing admin and RBAC permission decorators to model credentials GET endpoints (#40962)** (a7a30b2)
- **fix(agent): clean legacy Agent Soul files (#41024)** (cbd78c0)
- **fix(dify-agent): add reliable shellctl stdio mode (#39997)** (005edb7)
- **fix(dify-agent): adjust local sandbox home paths (#41021)** (b034368)
- **fix(api): enforce admin and RBAC permissions on tool OAuth custom client GET endpoint (#40944) (#40945)** (43b6d8e)
- **fix(snippet): support snippet history version export (#41012)** (248df5d)
- **fix(api): handle suspended email domains (#41004)** (a6ace29)
- **fix(agent): complete ownership-aware deletion lifecycle (#40888)** (013b328)
- **fix(snippets): implement delete for published snippet workflow versions (#41003)** (d7b1531)
- **fix(billing): remove misleading tax assurance (#41009)** (63acefa)
- **fix(web): clarify agent deletion consequences (#41002)** (2daa69c)

### Tests
- **test: migrate RAG variable controller sessions and ORM models to SQLite (#40609)** (48315be)
- **test: migrate step-by-step tour sessions to SQLite (#40636)** (a9035a3)
- **test(vdb): use real ORM models in provider tests (#40687)** (39ce9f6)
- **test: move pure integration cases to unit tests (#40705)** (ed9d380)
- **test: centralize app and account config overrides (#40860)** (f3bb73b)
- **test(cli): tsconfig gap (#41224)** (caf7e90)
- **test: remove obsolete integration coverage (#40704)** (cfae251)
- **test: migrate trigger and webhook sessions and ORM models to SQLite (#40594)** (bda6bf3)
- **test: migrate console dataset segment sessions and ORM models to SQLite (#40515)** (92978f6)
- **test: migrate residual app generator ORM models to SQLite (#40580)** (6fe87aa)
- **test: migrate console agent skill ORM models to SQLite (#40570)** (37a927b)
- **test: migrate auth and access controller ORM models to SQLite (#40572)** (7d635d9)
- **test: migrate console app sessions and ORM models to SQLite (#40559)** (0ce41bf)
- **test: migrate remaining controller sessions and ORM models to SQLite (#40538)** (92b93c9)
- **test: migrate Agent App session store to SQLite ORM (#40638)** (4692741)
- **test: migrate vector space admission sessions and ORM models to SQLite (#40640)** (4ca0a10)
- **test: add tmp_path type (#40724)** (6ce0976)
- **test: migrate annotation sessions and ORM models to SQLite (#40504)** (5827ce2)
- **test: centralize typed runtime config overrides (#40857)** (502418f)
- **test: migrate snippet service ORM models to SQLite (#40567)** (6e89052)
- **test: migrate media and execution service sessions and ORM models to SQLite (#40552)** (e27eb51)
- **test: migrate Explore controller sessions and ORM models to SQLite (#40537)** (2155adf)

### Docs
- **docs: fix dead anchors in localized READMEs and stale dify-agent link (#41101)** (9d6c846)
- **docs: add Sealos deployment option (#41026)** (0c3d08f)
- **Reorganize UI documentation structure** — Documentation for the Dify UI component library has been restructured into a clearer hierarchy with dedicated guides for forms, overlays, selection, styling, testing, and authoring. Individual component README files have also been added for better discoverability. (ca6f4e1)

### Chore
- **chore: bump version to 1.17.0 (#41247)** (09a855d)
- **refactor(web): migrate dataset rename form (#41233)** (8abff1b)
- **refactor(web): migrate pipeline DSL import form (#41232)** (eb7a182)
- **refactor(api): complete account education boundary (#41153)** (ef92cb7)
- **chore(deps): bump boto3 from 1.43.71 to 1.43.76 in /api in the storage group (#41126)** (c9ea15a)
- **chore(i18n): sync translations with en-US (#41173)** (b9764c4)
- **ci: add HITL IM test environment deployment (#41171)** (4f8a4c2)
- **chore(api): enforce backend layer boundaries (#41159)** (2e1620c)
- **chore: show full agent save time on hover (#41148)** (7ce751f)
- **chore(deps): upgrade pnpm workspace dependencies (#41138)** (643e2d6)
- **chore: Replace star image with new asset link (#41136)** (0ab88ef)
- **refactor(web): migrate pipeline publishing input form (#41129)** (7b3d97c)
- **refactor(web): migrate pipeline template input form (#41128)** (429edf4)
- **refactor(web): migrate duplicate app input form (#41127)** (5a9b6cb)
- **chore(deps): bump gunicorn from 26.0.0 to 26.1.0 in /api in the flask group (#41118)** (77998e4)
- **refactor: pass session to workflow comment account accessors (#41117)** (aed1672)
- **chore(deps): bump the github-actions-dependencies group with 4 updates (#41120)** (11c922b)
- **refactor(web): use shared session factory for JWT decoding (#41007)** (ccd0f4b)
- **refactor(api): standardize session factory wiring (#41085)** (5018f8a)
- **refactor(api): standardize console billing portal errors (#41055)** (ed45016)
- **refactor(dify-ui): rename radio family entrypoint (#41104)** (c62947f)
- **refactor(dify-ui): simplify overlay content APIs (#41098)** (e18310e)
- **refactor(dify-ui): simplify popover content API (#41069)** (a9b8c84)
- **refactor(agent): simplify Agent v2 output contract (#41062)** (35a4533)
- **refactor(dify-ui): compose dialog close controls (#41064)** (6cb96ad)
- **refactor(api): finish account controller application boundary (#40440)** (b38d907)
- **refactor(api): extract change email state machine (#40439)** (a52adef)
- **refactor(api): move account lifecycle into application services (#40438)** (3b05b5e)
- **refactor(web): migrate external API input fields (#41052)** (44e89d8)
- **refactor(web): migrate subscription confirmation input (#41051)** (7b1339a)
- **refactor(web): migrate human input timeout field (#41050)** (2ff3f7b)
- **refactor(api): move account access behind application services (#40437)** (1d79b87)
- **Refactored slider component structure** — The slider component was restructured to expose its anatomy following Base UI standards, making it more flexible for different use cases across the application. This involved updating slider implementations throughout forms, workflows, and configuration panels to use the new anatomy pattern. (720e1fa)
- **Updated AI Platform library** — Upgraded the Google Cloud AI Platform dependency from version 1.160.0 to 1.164.0 to access latest features and improvements. (c7b5a45)
- **Update storage dependency libraries** — Updated AWS boto3 to version 1.43.71 and Google Cloud Storage to version 3.13.1 to bring in the latest bug fixes and improvements for cloud storage operations. (0c69874)
- **refactor(web): migrate empty dataset input (#41030)** (f4e50f3)
- **refactor(web): migrate document rename input (#41029)** (aba3f9c)
- **refactor(web): migrate conversation rename input (#41028)** (979c8cc)
- **refactor(api): replace legacy recommended app retrieval stack (#40395)** (1bb9183)
- **refactor(api): decouple recommended app runtime admission (#40257)** (de7e43a)
- **refactor(api): isolate trial app usage writes (#40208)** (b09691e)
- **refactor(api): decouple console tag management (#40843)** (6f70ca8)
- **refactor(dify-agent): use Workspace as shell temp space (#41023)** (97a3039)
- **refactor(api): extract recommended app query service (#40207)** (f97fc01)
- **chore: inline custom ESLint rules (#41008)** (e2f6418)
- **refactor: consolidate frontend browser test infrastructure (#40997)** (72b6a4e)
- **refactor(web): migrate install account fields (#40992)** (b16a24f)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/langgenius/dify?utm_source=github-action)._