## langgenius/dify — 1.17.0…1.17.1

_419+ commits._

### Features
- **feat(nuqs-jotai): bridge nuqs URL state into Jotai (#42086)** (7f59b65)
- **feat: add agent resource permissions (#41940)** (f89c3e6)
- **feat: support keyboard movement for workflow nodes and comments (#41967)** (93d6ff3)
- **feat(rbac): agent RBAC/ACL scenes and resource-locator check bundles (#41768)** (86134ea)

### Fixes
- **fix(web): delegate overlay initial focus to popup owners (#42121)** (2c206d2)
- **fix(web): center settings dialog across viewport sizes (#42120)** (b3c978c)
- **fix(web): correct form labels, validation feedback, and keyboard navigation (#42096)** (1a415d1)
- **fix(ui): let collapsible consumers own trigger styling (#42116)** (445b194)
- **fix(web): preserve web apps navigation focus and disclosure semantics (#42113)** (44dac4a)
- **fix(api): restore Human Input completion events (#42082)** (798fd5e)
- **fix(agent): pin chatflow participant versions across config updates (#42105)** (c3f603c)
- **fix(dify-ui): preserve invalid focus colors and remove shadow transitions (#42108)** (1dcfe38)
- **fix(web): remove local search delay and clean up component lifecycles (#42102)** (f1da874)
- **fix: fix agent.id mismatch lead permission keys are empty (#42095)** (63bd623)
- **fix(web): restore content-sized search shortcut keycap (#42097)** (3e44b51)
- **fix(web): stabilize install footer and shortcut initial rendering (#42088)** (5f02726)
- **fix(web): prefetch skill feature flag for initial navigation (#41731)** (d4d2a4a)
- **fix(ci): refresh E2E runtime path filters (#42079)** (5feddcb)
- **fix: prevent note bold shortcut from toggling the sidebar (#42078)** (bce802c)
- **fix(web): align card tag masks with design tokens (#42074)** (40955e7)
- **fix(web): restore focus after closing overlays (#42068)** (06f5880)
- **fix(web): open embedded recommend banner templates in the detail dialog (#42063)** (8c5dd51)
- **fix: fix undo delete operation for webhook trigger node lead the url … (#42069)** (adedbf1)
- **fix(web): hide decorative content and redundant list semantics (#42060)** (e8c3419)
- **fix: make sortable lists keyboard accessible (#41974)** (b577502)
- **fix: join all rich_text/title segments in Notion database extraction (#42050)** (6e91ee2)
- **fix: escape double quotes in .xls cell values like the .xlsx path (#42049)** (112e33a)
- **fix(console): stop advertising the education plan outside Dify Cloud (#41898)** (8a69aa2)
- **fix: deduplicate repeated GET request error notifications (#42035)** (0669e4e)
- **fix(api): accept valid epoch-0 timestamps in localtime conversion tool (#42027)** (0b8435d)
- **fix: keep Notion table cell rich text segments in one Markdown column (#41993)** (4559510)
- **fix(api): handle invalid app icon references (#41977)** (0c443b7)
- **fix(api): reject trailing newlines in user_input_form variable names (#42029)** (cc44574)
- **fix: validate declared blob size before allocating buffer in chunk merger (#42021)** (75f203c)
- **fix(api): fall back to first server URL when X-Request-Env is set but servers lack env key (#42025)** (da6a1b0)
- **fix: dataset hitcount deadlock (#41979)** (bb2945a)
- **fix(dataset): clean multimodal attachments during reindex (#41999)** (89df7a6)
- **fix(api): allow PDF extraction from URLs without an upload file (#41950)** (fc062bf)
- **fix(api): resolve aliases in remote settings sources (#41463)** (e34b2f9)
- **fix(web): keep recommend banner logos intact and show template authors (#41980)** (dfe5d8a)
- **fix(api): flatten readabilipy plain_text items in web reader tool (#41954)** (09ddcbe)
- **fix: restore comment marker focus after closing threads (#41978)** (e75b5f6)
- **fix(web): reset goto anything search after dialog closes (#41976)** (0955b8b)
- **fix(api): accept CRLF SKILL.md when importing skill zips (#41657)** (c9e0118)
- **fix(api): correct service api rate limit descriptions (#41975)** (2f00e64)
- **fix(api): handle string and missing params in weekday time tool (#41952)** (80428a6)
- **fix(rag): preserve CSV cell text during knowledge import (#41922)** (f3154e3)
- **fix(i18n): sync agent access point copy (#41969)** (2873abd)
- **fix(api): anchor JSON extraction on brackets in parse_json_markdown (#41959)** (67f7a55)
- **fix(dataset): delete segment attachment blobs from storage (#41400)** (2cdfe24)
- **fix: make panel and node resizing keyboard accessible (#41963)** (a233b2f)
- **fix(api): enforce RBAC permission on MCP tool provider GET endpoint (#41547) (#41548)** (a67f62e)
- **fix: correct page landmarks and document layout rules (#41938)** (efe506a)
- **fix(api): align service api schemas with runtime behavior (#41943)** (7ba2cfb)
- **fix(agent): persist Chatflow Agent V2 memory by conversation_id (#41871)** (c157e59)
- **fix(vdb-weaviate): backward-compatible cleanup + preserve positional alignment (#41915)** (216180c)
- **fix(dataset_service): refresh session snapshot before UploadFile lookup (#41840)** (eeff2c0)
- **fix(billing): align zero and unlimited quota semantics (#41927)** (4f463b1)
- **fix(api): reject ownerless pending DSL imports (#40107)** (a9cb17e)
- **fix(dx): repair and restage Python files in pre-commit (#41877)** (715bc7c)
- **fix(api): fix tencent summary vector deadlock (#41916)** (60656a6)
- **fix(ssrf): apply private allowlist to agent_ssrf_proxy (#41870)** (c7423ff)
- **fix(web): use default Code Inspector integration (#41903)** (40f0b8a)
- **fix(agent): send uploaded images as native multimodal input (#41685)** (cf34e3e)

### Tests
- **test: migrate RAG retrieval sessions and ORM models to SQLite (#40512)** (31dfa21)
- **test: move mocked model and tool cases to unit tests (#40708)** (3ecceb7)
- **test: migrate agent workspace and publishing sessions and ORM models to SQLite (#40506)** (a43583a)
- **test: migrate Service API app sessions and ORM models to SQLite (#40558)** (c529c3b)
- **test: migrate console dataset metadata sessions and ORM models to SQLite (#40520)** (e7cfe14)
- **test: migrate custom tool provider ORM model to real entity (#40653)** (4e0d7f7)
- **test: migrate summary index sessions and ORM models to SQLite (#40505)** (d201dc1)
- **test: split CodeNode validation from sandbox coverage (#40707)** (608b1d1)
- **test: migrate console workflow sessions and ORM models to SQLite (#40563)** (f71047f)
- **test: migrate console app response sessions and ORM models to SQLite (#40562)** (a062155)
- **test: migrate workflow node execution task sessions and ORM models to SQLite (#40571)** (4f29213)
- **test: reclassify response filter regressions (#40706)** (62adebc)
- **test: migrate segment service sessions and ORM models to SQLite (#40535)** (398addf)
- **test: migrate console dataset document sessions and ORM models to SQLite (#40522)** (1c4bcff)
- **test: migrate workspace snippet sessions and ORM models to SQLite (#40524)** (bcda6b4)
- **test: migrate provider core entity sessions and ORM models to SQLite (#40532)** (e4eb3d0)

### Docs
- **docs(api): fix working directory instructions for running tests (#42085)** (90aa225)
- **docs(CODEOWNERS): Assign domain owners for backend test paths (#42007)** (d60873d)

### Chore
- **chore: bump version to 1.17.1 (#42129)** (8387590)
- **chore(web): upgrade React to 19.3 and adopt browser-only rendering (#42093)** (f1d88f7)
- **chore(codeowners): assign dify-agent to Yanli (#42091)** (dfe27fc)
- **refactor(api): remove legacy end user type fallback (#39662)** (8bdf01b)
- **chore: fit the app canvas when create from DSL and preview (#42073)** (9e6c0c2)
- **chore(deps): bump the google group across 1 directory with 2 updates (#41121)** (e7eb030)
- **chore(deps): bump unstructured from 0.21.5 to 0.24.0 in /dify-agent (#41765)** (8c208ad)
- **refactor(api): migrate remaining RESTX models to Pydantic (#40399)** (4724779)
- **refactor(web): migrate conversation variable inputs (#42070)** (f70cea5)
- **chore(deps): bump gunicorn from 26.1.0 to 26.2.0 in /api in the flask group across 1 directory (#41505)** (0468eee)
- **chore(release): Upgrade self-hosted Weaviate to 1.39 (#38214)** (647fec5)
- **chore(deps): bump the storage group across 1 directory with 4 updates (#41893)** (a1a1a42)
- **chore(deps): bump httpx2 from 2.5.0 to 2.12.0 in /dify-agent (#42011)** (87b4de1)
- **chore(deps): bump httpx2 from 2.5.0 to 2.12.0 in /api (#42012)** (1007cf8)
- **chore(i18n): sync translations with en-US (#42064)** (57a6ccb)
- **chore(deps): bump h2 from 4.3.0 to 4.4.1 in /dify-agent (#40119)** (ebb875e)
- **chore: example to add Mapped (#40374)** (677f2cf)
- **chore(deps): bump unstructured from 0.21.5 to 0.27.5 in /api (#42053)** (a7cc691)
- **chore(lint): respect gitignore in ESLint flat config (#42065)** (8e8a3c5)
- **chore(lint): tighten inline disable enforcement (#42058)** (0f232ac)
- **chore(deps): bump transformers from 5.6.2 to 5.16.1 in /dify-agent (#42054)** (4223b8e)
- **refactor(web): migrate workflow numeric configuration inputs (#42052)** (603176c)
- **chore(lint): share and tighten JSX accessibility rules (#42045)** (cb1a896)
- **refactor(controllers/console): inject saved-message query with @model_validate (#41819)** (3f76dbe)
- **refactor(api): remove InstalledApp implicit-session accessor (#42000)** (cd031ab)
- **refactor(models): remove the App.bound_agent_id and App.is_agent wrappers (#41998)** (dc9dd9c)
- **refactor(models): remove the unread App.author_name db.session wrapper (#41983)** (e65f45f)
- **chore(deps): bump gitpython from 3.1.58 to 3.1.59 in /api (#42017)** (f1c2917)
- **chore(deps): upgrade jotai to v3 and jotai-scope (#42036)** (bb17977)
- **chore(deps): upgrade pnpm to 12.3.4 and Vite+ to 0.3.1 (#42005)** (bec2c67)
- **refactor(models): pass session into WorkflowNodeExecutionModel accessors (#41968)** (f3e5f41)
- **refactor(web): isolate pricing modal state and lifecycle (#41960)** (12d2306)
- **refactor(models): remove four unread legacy db.session wrappers (#41964)** (9e0763e)
- **refactor(models): remove the legacy db.session wrappers on App (#41942)** (970bbec)
- **refactor(api): trim workspace features response contract (#41948)** (8acdb15)
- **refactor(web): retire provider context (#41944)** (d978fe7)
- **refactor(api): extract plugin file upload application service (#41808)** (146b193)
- **refactor(web): move model lists out of provider context (#41939)** (1006519)
- **refactor(web): move provider feature flags to query consumers (#41937)** (e26dcf5)
- **refactor(api): extract tool file download service (#41790)** (d43a23d)
- **refactor(console): unify environment-aware oRPC clients and query policies (#41932)** (22189f6)
- **refactor(api): extract upload file delivery service (#41772)** (749d1f8)
- **refactor(web): remove obsolete agent v2 scaffolding and editor state (#41931)** (8980506)
- **refactor: add missing @override decorators to console controller classes (#37113)** (0df092d)
- **style(api): remove unnecessary type conversions in services, repositories and tests (#41856)** (d138eff)
- **refactor(models): pass session into InstalledApp.tenant accessor (#41831)** (a57e04a)
- **refactor: preserve exception context when re-raising in except blocks (#40432)** (93287f2)
- **refactor(web): retire provider context plan state (#41925)** (8fc11b2)
- **refactor(models): remove legacy db.session wrappers on Message accessors (#41886)** (75f867d)
- **refactor(models): remove the last standalone legacy db.session properties on Dataset (#41911)** (d5be01b)
- **refactor(models): pass session into ApiToolProvider.user accessor (#41882)** (b931014)
- **refactor(service-api): extract file preview application service (#41732)** (c17a96f)
- **refactor(api): remove legacy billing enabled state (#41917)** (eba589d)
- **refactor(web): remove legacy enableBilling consumers (#41913)** (fc01366)
- **refactor(web): remove provider plan query flags (#41908)** (5c0d3c4)
- **refactor(web): move app quota refresh out of provider context (#41906)** (3be0cab)
- **refactor(controllers): adopt with_session in web saved_message (#41859)** (5e51fe2)
- **refactor(models): pass session into CustomizedSnippet accessors (#40379)** (2df9220)
- **chore(i18n): sync translations with en-US (#41904)** (5f978fe)
- **refactor(models): remove remaining legacy db.session property wrappers on Dataset (#41647)** (11a9627)
- **refactor(models): remove legacy db.session property wrappers on DocumentSegment and DatasetQuery (#41794)** (62a2863)
- **refactor(controllers): inject message request models (#41884)** (d91672c)
- **refactor(inner_api): dep-inject workspace payloads with @model_validate (#41540)** (56a31ba)
- **refactor(models): remove legacy db.session wrappers on Message feedback/annotation accessors (#41883)** (a1a98e1)
- **refactor(models): pass session into AppAnnotationSetting.collection_binding_detail (#41885)** (80f6f72)
- **chore(deps-dev): bump the dev group in /api with 48 updates (#41896)** (60e983c)
- **refactor(web): migrate loop variable constant inputs (#41901)** (3e961db)
- **refactor(web): migrate workflow error default inputs (#41900)** (789cada)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/langgenius/dify?utm_source=github-action)._