mirror of
https://github.com/langflow-ai/langflow.git
synced 2026-07-24 01:22:23 +08:00
71fbf5ff005d7f2b63f22bbdaf43cc75190e8f9c
17523 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
| 71fbf5ff00 |
docs: cut version 1.9.0 (#12681)
* version-1.9.0-docs * [autofix.ci] apply automated fixes * [autofix.ci] apply automated fixes (attempt 2/3) --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> |
|||
| 2fa3d1c759 |
feat: add langflow-sdk support to release workflow (#12679)
* feat: add langflow-sdk build and publish support to release workflow Add support for building and publishing the langflow-sdk package in the release workflow, mirroring the nightly build support added in #12491. Changes: - Add `release_sdk` workflow input for controlling SDK release - Add `determine-sdk-version` job with first-release PyPI handling - Add `build-sdk` job with version verification and import testing - Add `publish-sdk` job that publishes SDK to PyPI before LFX - Update `build-lfx` to download SDK artifact and test both wheels together - Update `build-base` and `build-main` to use SDK wheel as find-links - Pass SDK artifact to cross-platform tests - Add validation: releasing LFX requires releasing SDK - Add pre-release version handling for SDK and LFX's SDK dependency * Update release.yml * Update release.yml * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
|||
| 389b11b884 |
docs: update wxo signup link (#12683)
Update wxo signup link: |
|||
| 40c5973292 |
fix: Allow >= specifications in dependencies (#12682)
* fix: Allow >= specifications in dependencies * [autofix.ci] apply automated fixes * [autofix.ci] apply automated fixes (attempt 2/3) --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> |
|||
| 19df4606ae |
chore: update deps (#12657)
* chore: update deps update deps due to sec vuln * chore: langchain-core>=1.2.28 langchain-core>=1.2.28 * chore: update pypdf pypdf 6.10 * chore: pyarrow, openai, litellm, mem0ai, toolguard picomatch, pyarrow, openai, litellm, mem0ai, toolguard * chore: override litellm * chore: match base uv.lock to root * chore: update tool.uv position update tool.uv position * chore: langflow-base[complete]>=0.9.0 langflow-base[complete]>=0.9.0 * chore: revert pyarrow revert pyarrow * chore: revert "lfx~=0.4.0", * chore: lfx white space * chore: remove allow-direct-references = true * chore: uv lock --upgrade after merge |
|||
| 26c415056c |
feat: add SHA-256 hash-based API key lookup (#12597)
* feat: add SHA-256 hash-based API key lookup Replace the O(n) full table scan in check_key with an indexed SHA-256 hash column for O(1) lookup. Legacy keys without a hash fall back to decrypt-and-compare and get their hash backfilled on first successful match. - Add api_key_hash column to ApiKey model (nullable, indexed) - Hash stored at key creation time - Migration adds column and backfills hashes for existing keys - Fail closed when multiple keys share the same hash - Remove unused fernet_obj parameter from decrypt_api_key * fix(migration): skip hashing duplicate-plaintext API keys Two-pass backfill: decrypt all rows, group by plaintext, then hash only unique-plaintext rows. Duplicate-plaintext groups are left with NULL hash so the runtime fast-path lookup cannot return multiple matches and fail closed. The runtime slow-path matches and backfills exactly one row per group on first use; remaining NULL rows become harmless orphans. Logs counts only (no key IDs or plaintexts) to avoid leaking operational info via deployment logs. Extracts _backfill_hashes helper for testing; adds 9 unit tests. --------- Co-authored-by: Eric Hare <ericrhare@gmail.com> |
|||
| 83acc4143d |
docs: mcp client and other changes (#12627)
* tools-component * tools-partial-and-release-notes * mcp-astra-changes * tutorial-changes * client-page-and-release-notes * langflow-mcp-client-for-coding-agents * fix-links * Apply suggestions from code review Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com> * include-explanation-for-step-4 --------- Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com> |
|||
| a425540bdb |
docs: add flow versioning (#12634)
* add-flow-versioning-and-release-note * add-flow-db-location |
|||
| 17ab88fca7 |
fix: fix base64 padding bug and empty Fernet error messages (#12595)
Extract shared `add_base64_padding` and `ensure_fernet_key` functions to eliminate duplicated key derivation logic between AuthService and auth/utils.py. Fix `_add_padding` adding 4 `=` characters instead of 0 when key length is a multiple of 4, which broke Fernet key derivation for 44-char keys. Change `%s` to `%r` in decryption failure logs so InvalidToken exceptions (which have no message string) render as `InvalidToken()` instead of empty strings. |
|||
| 95d4c94ef9 |
fix: upgrade playwright to 1.58.0 to address Chromium CVEs (#12668)
* fix: upgrade playwright to 1.58.0 to address Chromium CVEs - Add playwright>=1.58.0 to override-dependencies in pyproject.toml - Update uv.lock: playwright 1.49.0 -> 1.58.0, pyee 12.0.0 -> 13.0.1 - Fixes CVE-2026-2313, CVE-2026-2314, CVE-2026-2315, CVE-2026-2319, CVE-2026-2321, CVE-2026-2441, CVE-2026-2648, CVE-2026-2649 - Ensures Docker builds download updated Chromium with security patches * fix: update npm to latest version to address brace-expansion CVE-2026-33750 - Add npm update after Node.js installation in Dockerfile - Fixes CVE-2026-33750 in system npm's brace-expansion dependency - System npm had brace-expansion 2.0.2, update gets 5.0.5+ - Low risk change: npm is backward compatible, only affects CLI tool * revert: remove npm update from Dockerfile - npm update attempts were causing CI build failures - Bundled npm has issues but updating it is proving problematic - Focus on playwright CVE fix which is the primary concern - brace-expansion CVE-2026-33750 is lower priority (DoS only) --------- Co-authored-by: Janardan S Kavia <janardanskavia@Janardans-MacBook-Pro.local> |
|||
| 42e84d0fdf |
fix: resolve race condition in test_component_logging for Python 3.13 (#12676)
Replace queue.get_nowait() with asyncio.wait_for(queue.get(), timeout=5.0) to properly wait for async events in the queue, preventing QueueEmpty errors in Python 3.13. Fixes flaky test failure in release workflow. |
|||
| 4be5f7f52f |
chore(i18n): disable automatic browser language detection (#12671)
* chore(i18n): disable automatic browser language detection, hardcode English * chore(i18n): remove language selector from Settings page |
|||
| 2da54a50d1 |
fix(ui): show moved flow in destination project without page refresh (#12670)
* fix move flows folders * fix folder spec * fix folder spec test * [autofix.ci] apply automated fixes --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> |
|||
| 953ccd05c1 |
fix: Build the correct oauth callback URL for MCP Composer (#12662)
* fix: Build the correct oauth callback URL for MCP Composer * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Clean up the normalization function * Update service.py --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
|||
| ac414d369a |
fix: Root path option in settings for reverse proxy (#12603)
* fix: Root path option in settings for reverse proxy * Update test_security_cors.py * fix: Better test for middleware * Update test_security_cors.py * Update src/lfx/src/lfx/services/settings/base.py Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * Update src/backend/tests/unit/api/v1/test_mcp_reverse_proxy.py Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * [autofix.ci] apply automated fixes * Ruff fixes --------- Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> |
|||
| 0982030961 |
fix: Resolve relative path issues in bundled environment (#12625)
fix assistant path lfx Co-authored-by: Antônio Alexandre Borges Lima <104531655+AntonioABLima@users.noreply.github.com> |
|||
| a216aa9060 |
fix(ui): refactor connection panel and fix search empty state (#12659)
* fix(ui): refactor connection panel and fix search empty state rendering Extract connection state management into useConnectionPanelState hook and search/list UI into ConnectionSearchList component. Fixes bug where blank list items rendered before the empty state when search returned no results. * fix(ui): prevent modal jump when clicking connection items in Chrome Chrome scrolls the nearest scrollable ancestor when focusing sr-only inputs inside labels. Adding relative + overflow-hidden to the label contains the scroll-into-view behavior within the label bounds. |
|||
| 73a48b5810 |
docs: generate and bump open API spec to 1.9.0 (#12638)
generate-and-bump-openapi-spec-to-1.9.0 |
|||
| d698666a1f |
fix: restore webhook SSE authentication using FastAPI dependency injection (#12661)
fix sse webhook |
|||
| faac7ad007 |
fix: allow booleans, numbers, etc. in root-level tweaks (#12605)
fix: allow booleans, numbers, etc. in root-level tweaks (#11830) Widen the Tweaks schema to accept bool, int, and float values alongside str and dict, so scalar tweaks like {"stream": false} are no longer rejected by Pydantic validation. bool is listed before int in the union to prevent Pydantic from coercing booleans to integers (since bool is a subclass of int). Adds unit tests for boolean and numeric root-level tweaks, as well as direct Tweaks Pydantic model validation tests. Co-authored-by: Alex Kuligowski <alekuligowski@gmail.com> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> |
|||
| 7e786a728f |
fix: Raw input value leaks into Global Variables dropdown list (#12660)
* Variable input shown in dropdown * added testcases * [autofix.ci] apply automated fixes --------- Co-authored-by: Olayinka Adelakun <olayinkaadelakun@Olayinkas-MacBook-Pro.local> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> |
|||
| 349e78c758 |
fix: propagate resource-specific conflict error to api (#12580)
* fix: preserve resource-specific conflict mapping in wxo deployment flow - rename DeploymentConflictError to ResourceConflictError (with a backward-compatible alias) and propagate resource/resource_name across deployment error handling - extend raise_for_status_and_detail to accept explicit conflict hints and only infer resource/resource_name from provider detail as a fallback - update deployment mappers/helpers to use resource/resource_name and format conflict details from structured fields - add explicit conflict metadata at known wxo catch/re-raise points (connection/tool/agent paths) and enforce hint passing through raise_as_deployment_error - prevent create/update top-level handlers from over-tagging conflicts as agent when downstream errors are tool/connection conflicts - centralize create-agent provider error translation via raise_as_deployment_error - add/adjust unit tests for route handlers, mapper conflict formatting, wxo service conflict propagation, and lfx deployment exception behavior (including Simple_Agent regression) * remove DeploymentConflictError shim * pass resource_name only on creation paths * allow None * fix(deployments): simplify conflict mapping and tighten error handling Remove conflict-hint inference fallback, keep pass-through conflict detail formatting, tighten ClientAPIException status extraction, and drop temporary debug prints in deployment error paths. * fix(deployments): simplify conflict hint mapping and align test expectations Remove redundant conflict-hint normalization in deployment exceptions, clarify base mapper conflict-detail docs, and improve invalid flow-version guidance. Update watsonx deployment tests to assert current service-layer conflict/resource and exception-chain behavior. * get rid of tool name fallbacks * hard code fallback message |
|||
| 5cb8567130 |
fix: make logs and outputs visible for components in tool mode (#11923)
* fix: display proper tool name and description in tool mode output When a component runs as a tool (connected to an Agent), the output modal now shows the proper tool name, description, and tags instead of "Tool 1". This builds tool metadata from the component's output method name and description for proper display in the ToolOutputDisplay component. * test: add unit tests for tool mode event emission Add tests to verify that components running in tool mode properly emit events to the frontend for logs visibility and tool metadata display. * [autofix.ci] apply automated fixes * fix: use public accessor for component logs instead of private attribute Add get_logs() method to Component class and use it in component_tool.py to fix Ruff SLF001 (private-member-access) violation flagged by CodeRabbit. * fix: emit real-time log SSE events for components running in tool mode - Set _current_output = TOOL_OUTPUT_NAME in tool wrappers so self.log() fires and logs are attributed to the component_as_tool output - Register on_log event in EventManager with thread-safe queue enqueue via call_soon_threadsafe for sync tools running in thread executor - Register on_log in production event manager (JobQueueService) - Add appendLogToFlowPool Zustand action to incrementally add logs - Handle "log" SSE event in buildUtils to update flowPool in real-time - Fix displayOutputPreview to also check data.logs[outputName].length * [autofix.ci] apply automated fixes * [autofix.ci] apply automated fixes (attempt 2/3) * [autofix.ci] apply automated fixes (attempt 3/3) * fix: address PR review issues for tool mode logs visibility - Fix TypeError: add output_name param to _build_output_function and _build_output_async_function (called with 4 args but only took 3) - Fix double-dispatch bug in event_manager.send_event: separate loop detection from queue dispatch to avoid misdiagnosing queue RuntimeErrors - Improve event_manager error handling: warn on QueueFull, error with traceback on unexpected failures, warn when loop is unavailable - Fix TypeScript type: VertexDataTypeAPI.logs uses LogsLogType[] (array) and remove the 3 as any casts in appendLogToFlowPool - Add input validation in buildUtils.ts log event handler to guard against undefined keys corrupting the flow pool - Add server-side logger.error on tool execution failure with exc_info - Fix tests: replace end_vertex assertions (never emitted by tool path) with build_end/log assertions; add LoggingCalculator subclass to test real-time log event emission Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * [autofix.ci] apply automated fixes * fix: store tool mode logs under component_as_tool output key - In get_tools(), pass TOOL_OUTPUT_NAME instead of output.name to _build_output_function/_build_output_async_function so self.log() events are stored under 'component_as_tool' key in flowPool, matching what the component_as_tool output's inspect modal reads - Fix emptyOutput in NodeOutputfield to return false when logs exist, preventing disabledInspectButton being vacuously true when outputs={} - Fix TypeScript undefined index type on internalOutputName in both displayOutputPreview and emptyOutput checks * fix: address ruff violations and test failures in tool mode logs - Fix ruff I001/SIM117/F401/TRY003/EM101 violations in test_component_toolkit.py - Replace private _event_manager/_current_output access with public setters in component_tool.py - Add set_current_output() public method to Component - Fix send_event() to call put_nowait directly in sync context (no event loop) - Fix _build_output_function/async to use getattr default fallback for non-component methods - Fix tests to use constructor-based _id to survive __deepcopy__ - Add TypeError guard in _get_method_return_type for mocked methods - Remove incorrect pytest.raises(ToolException) since handle_tool_error=True swallows it * fix: handle array logs in switchOutputView and guard build_end/log events - Export onEvent for testability - Guard build_end event against missing data.id to prevent state corruption - Type results as OutputLogType | LogsLogType[] in SwitchOutputView to handle tool mode logs arriving as an array - Guard resultType/resultMessage against array case to prevent crashes - Add tests for onEvent log/build_end paths and appendLogToFlowPool store method * [autofix.ci] apply automated fixes --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
|||
| da24dfad61 |
docs: components index path env var (#12630)
* env-var * allowlist-for-custom-components * clarify-which-wins |
|||
| e89c124153 |
feat: harden /variables/detections to return only global variables (#12650)
* refactor: simplify /variables/detections to return only verified global variable names Drop the two-tier detection model (load_from_db + password-field heuristics) in favor of a single source: fields with load_from_db=True. Candidates are cross-checked against the user's existing global variables before being returned, preventing accidental secret leakage via template values. - Remove DetectedEnvVar model and unresolved_ids from the response - Flatten response to list[str] of verified global variable names - Fail fast (404/422) on missing or malformed flow versions - Add min_length=1 validation on flow_version_ids - Update frontend types and consumers to match simplified response * refactor: batch flow-version loading for variable detection Reduce /variables/detections query fanout by fetching flow versions in one CRUD call and validating IDs up front in the request schema. Add a bounded filter-size guard in flow_version CRUD, keep payload-shape validation explicit in the endpoint, and align unit/API tests with the new batch helper path. - Deduplicate DetectVarsRequest.flow_version_ids via schema validation - Add get_flow_version_entries_by_ids() with MAX_VERSION_ID_FILTER_SIZE guard - Replace per-ID flow-version lookups in detect_env_vars with one batch fetch - Update detect-env-vars unit tests to mock the batch helper and cover dedup/validation paths - Add CRUD guard test for oversized ID filters - Update variable endpoint tests to patch get_flow_version_entries_by_ids |
|||
| d40e316622 |
feat(templates): replace AstraDB with native Knowledge Base in Vector Store RAG (#12629)
* feat(templates): replace AstraDB with native Knowledge Base in Vector Store RAG starter project Swaps the AstraDB vector store components for Langflow's native KnowledgeIngestion and KnowledgeBase components, removing the need for external Astra credentials. Updates README and Load Data notes to reflect the new components, removes the disconnected AstraDB node, and updates the template tags accordingly. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix: clean up hardcoded local state from template export - clear REDACTED api_key placeholder - clear hardcoded knowledge_base name "release" - clear hardcoded model options (populated dynamically at runtime) * Sanitize the KB options * Sanitize the KB options --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: ogabrielluiz <gabriel@langflow.org> Co-authored-by: Eric Hare <ericrhare@gmail.com> |
|||
| 922e7310fc |
fix: Make sure flow upgrades work with Agent component and ModelInputs generally (#12620)
* fix: Flow upgrade works for Agent component * Add test coverage * Better behavior for model providers * Update index.tsx * Combobox in language model * [autofix.ci] apply automated fixes * [autofix.ci] apply automated fixes (attempt 2/3) * [autofix.ci] apply automated fixes (attempt 3/3) * Update test_unified_models.py * Update index.tsx * Make sure all templates start with blank options for MI * Make sure all templates start with blank options for MI * Update test_flow_requirements.py * Update component_index.json --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> |
|||
| cfaba3ede7 |
fix: Remove redundant api key field in KB Ingest (#12624)
* fix: Remove redundant api key field in KB Ingest * Update component_index.json |
|||
| ca8547b6e6 |
fix: MCP Tools loses optional field types (#12622)
* fix: MCP Tools loses optional field types * [autofix.ci] apply automated fixes * [autofix.ci] apply automated fixes (attempt 2/3) * [autofix.ci] apply automated fixes (attempt 3/3) --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> |
|||
| 3fba536f03 |
fix(ui): Show welcome page for new users when AUTO_LOGIN is false (#12626)
* fix page displayed on AUTO LOGIN false * fix: translate Portuguese test comments to English --------- Co-authored-by: ogabrielluiz <gabriel@langflow.org> |
|||
| 976bb699ce | fix: Update WXO tests for handling none keys (#12636) | |||
| 2cc8460f2a | fix: Remove test that doesnt test anything (#12633) | |||
| 4eb35b2261 |
feat: add project_id query param to list /deployments endpoint (#12574)
* feat: add project_id query parameter to deployments list endpoint Allow filtering GET /api/v1/deployments by project (folder) via an optional project_id query param. Threaded through list_deployments_synced, list_deployments_page, and count_deployments_by_provider. Rejected with 422 when combined with load_from_provider=true. * make FE use project_id query param for listing deployments * friendly message * feat: send project_id when creating a deployment from the frontend Resolve the current project context (flow's folder_id, URL folderId, or default collection) and pass it as project_id in the deployment create payload so deployments are scoped to the active project. * test(deployments): add project-scoped filter coverage Add database-backed tests that assert deployment list and count queries return only records for the requested project_id. |
|||
| 75e596a4af |
feat: wxo api provider data url for provider accounts (#12607)
* feat: deployment page list
* feat: add deployment stepper modal with context-based state management
Implement a multi-step deployment creation flow with 4 steps (Provider,
Type, Attach Flows, Review). State is centralized in a scoped
DeploymentStepperContext to avoid prop-drilling across step components.
Includes bug fixes for version re-selection and connection pre-selection.
* feat: replace mock flows and versions with real API data in deployment stepper
Fetch real flows from the API (scoped to current folder) and versions
per-flow lazily when selected. Enrich selectedVersionByFlow context to
store versionTag alongside versionId so the review step can display it
without re-fetching. Remove MOCK_FLOWS_WITH_VERSIONS from mock-data.
* refactor: improve deployment stepper code quality and conventions
Rename all new deployment files to kebab-case per project conventions,
fix context re-render issues with useMemo/useCallback, replace raw
Tailwind colors with design tokens, add missing data-testid and ARIA
attributes, fix Deploy button disabled on review step, and move shared
FlowTabType to a dedicated types file.
* refactor: align deployment provider types and UI to backend contracts
- Rename ProviderInstance -> ProviderAccount to match backend naming
- Update ProviderAccount fields to match DeploymentProviderAccountGetResponse (provider_key, provider_url, provider_tenant_id, created_at, updated_at)
- Update ProviderCredentials fields to match DeploymentProviderAccountCreateRequest (provider_key, provider_url, api_key)
- Rename all "instance" UI terminology to "environment" (tabs, labels, components)
- Auto-select watsonx Orchestrate on mount as the only supported provider
- Remove Kubernetes from mock providers; update mock data to use watsonx_orchestrate only
* feat: add react-query hooks for deployments and provider accounts with mock data
- Add useGetProviderAccounts hook (GET /deployments/providers) replacing direct MOCK_PROVIDER_INSTANCES import in step-provider.tsx
- Add useGetDeployments hook (GET /deployments) replacing direct MOCK_DEPLOYMENTS import in deployments-page.tsx
- Replace fake setTimeout loading state with hook isLoading state
- Register DEPLOYMENTS and DEPLOYMENT_PROVIDER_ACCOUNTS URL constants
- Real API calls are commented out with TODO markers for easy swap when backend is ready
* chore: remove stale biome-ignore suppression in step-attach-flows
* fix: replace button role=radio with semantic input type=radio in ProviderCard
* fix: replace button role=radio with semantic radio inputs across deployment stepper
- Extract RadioSelectItem component (label + sr-only input + checkbox indicator)
used by version, connection, and environment selectors
- Fix step-type.tsx type cards with label/input pattern (matching ProviderCard)
- Add role="radiogroup" wrapper to EnvironmentList
- Fix envVars key: use stable crypto.randomUUID() id instead of array index
* feat: add name field to provider accounts, multi-select connections, and real API call
- Add `name` field to ProviderAccount, ProviderCredentials, and mock data
- Switch connection selection from single to multi-select (CheckboxSelectItem)
- Allow creating new connections inline from the attach flows step
- Lift connections state up to DeploymentStepperContext
- Move ConnectionItem type from step-attach-flows to shared types.ts
- Wire up real API call in useGetProviderAccounts (remove mock)
* feat: wire deploy button and populate deployments page with real API data
- Add usePostDeployment and usePostProviderAccount mutation hooks
- Wire Deploy button in stepper modal: creates provider account if needed,
then POSTs to /api/v1/deployments with WXO provider_data shape
- Fix environment_variables payload: wrap values as { value, source: "raw" }
to satisfy EnvVarValueSpec schema
- Fix connection app_id: prefix with conn_ so WXO name validation passes
(names must start with a letter)
- Multi-select connections with checkbox UI; persist connections in context
so they survive back/forward navigation
- Update Deployment type to match API response shape; remove mock fields
(url, status, health, lastModifiedBy)
- Wire useGetDeployments to real API; load provider ID from useGetProviderAccounts
- Update deployments table to display real fields: name, type, attached_count,
provider name, updated_at
* refactor: extract DeploymentsContent component to eliminate nested ternary
* feat: add Test Deployment chat modal for deployed agents
Implements a chat interface to test deployments directly from the UI.
Wires up two entry points: the stepper modal "Test" button (inline
transition) and the deployments table play button (standalone dialog).
- Add usePostDeploymentExecution and useGetDeploymentExecution hooks
hitting POST/GET /api/v1/deployments/executions
- Build test-deployment-modal: ChatHeader, ChatMessages, ChatInput,
ChatMessageBubble with user/bot avatars, loading dots, tool traces
- useDeploymentChat hook: recursive setTimeout polling (max 30 × 1.5s),
thread_id persistence for multi-turn, watsonx response parsing
(response_type/type text, wxo_thread_id extraction)
- Stepper modal transitions inline to TestDeploymentContent on Test click
- Deployments table play button opens standalone TestDeploymentModal
* feat: add syntax highlighting to chat code blocks using SimplifiedCodeTabComponent
* feat: add action menu and icon-based type badge to deployments table
- Add dropdown action menu (Duplicate, Update, Delete) to each row
- Replace left-border type badge with icon-based badge (Bot for Agent, Plug for MCP)
* refactor: remove connected status from provider card in stepper
* feat: auto-detect flow env vars in deployment connection form
- Add POST /deployments/variables/detections backend endpoint that scans
flow version data for credential fields (load_from_db=True globals and
password=True fallbacks) and returns detected variable names
- Derive meaningful env var names from the model field's category when no
global variable is linked (e.g. OPENAI_API_KEY from category "OpenAI")
- Add DetectEnvVarsRequest/DetectedEnvVar/DetectEnvVarsResponse schemas
- Add usePostDetectDeploymentEnvVars frontend mutation hook
- Pre-populate Create Connection env var rows with detected keys/values
when attaching a flow version; global variable selections render as tags
via InputComponent with global variable picker support
* feat: add empty state and smart default tab for available connections
- Default to "Create Connection" tab when no connections exist
- Show empty state with icon, description, and shortcut link when
the Available Connections tab has no items
* feat: redesign review step with two-column layout and env vars section
Match new design reference with Deployment/Attached Flows columns
and a masked Configuration section showing env variable keys.
* feat: integrate delete deployment with loading state and fix test modal flow
- Add useDeleteDeployment hook (DELETE /deployments/{id}, refetches list)
- Show spinner + faded row while deletion is in progress; fix race where
deleteTarget was cleared before isPending resolved by using separate deletingId state
- Redesign StepDeployStatus with animated spinner, ping ring, and success checkmark
- After deploy, "Test" closes the stepper and opens the standalone TestDeploymentModal
(consistent UI, correct providerId, chat reset on close)
- Prevent closing the stepper modal while deployment is in progress
* refactor: address PR review concerns for deployment UI
- Split step-attach-flows.tsx (656→274 lines) into FlowListPanel,
VersionPanel, and ConnectionPanel sub-components
- Extract Watsonx parser utilities into watsonx-result-parsers.ts,
reducing use-deployment-chat.ts from 384 to 277 lines
- Surface detectEnvVars errors via setErrorData instead of silently
resetting state
- Add EnvVarEntry named type to types.ts, replacing inline shape
repeated across two files
- Move import json to module level in deployments.py (PEP 8)
- Fix URL construction in useGetDeploymentExecution to use axios
params option, consistent with other hooks
- Remove commented-out MOCK_CONNECTIONS dead code
- Add TODO comment to hardcoded "watsonx-orchestrate" provider key
* refactor: apply React best practices and remove mock data from deployment UI
- Fix barrel imports: import directly from source files in deployments-page,
step-provider, and step-attach-flows
- Replace useEffect auto-select with derived effectiveFlowId in step-attach-flows
- Fix async state init bug for environmentTab using useRef guard pattern
- Fix stale closure in handleAddEnvVar with functional setState
- Wrap useState initial value in lazy initializer for envVars
- Wrap all 8 handlers in useCallback; wrap panel components in memo()
- Remove mock-data.ts; move PROVIDERS constant inline to step-provider
- Drop MOCK_CONNECTIONS (was empty array) from context
- Simplify step-provider UI: remove provider selection radio group since
only one provider exists; show watsonx Orchestrate as a static display
* feat: add Deploy button to canvas toolbar
Adds a primary-colored Deploy button at the far right of the canvas toolbar.
Clicking it saves the flow, creates a version snapshot, and opens the
deployment stepper modal with the current flow and version pre-selected in
the Attach Flows step, including auto-detection of environment variable keys.
* chore: disable ENABLE_DEPLOYMENTS feature flag
* fix: forward LANGFLOW_FEATURE_WXO_DEPLOYMENTS env var to frontend
The feature flag was reading from import.meta.env but the variable
was never injected by Vite's define config, so the deployments
feature was always disabled regardless of the .env value.
* feat: implement providers tab with environment list
Replace the "coming soon" placeholder in the Providers sub-tab with a
real table showing existing provider accounts (name, URL, provider key,
created date) fetched from the API, including loading skeleton and
empty state.
* feat: add provider creation modal with tab-aware action button
Create AddProviderModal with name, API key, and URL fields matching
the deploy modal. The top-right button now switches between
"New Deployment" and "New Environment" based on the active sub-tab.
* feat: implement provider account deletion with confirmation modal
Add useDeleteProviderAccount hook, wire it through ProvidersContent
and ProvidersTable with loading/disabled row state on delete, and
reuse DeleteConfirmationModal for the confirmation flow.
* fix: correct provider_key to watsonx-orchestrate and add API key visibility toggle
Fix the provider_key value sent to the API. Add eye/eye-off toggle
to the API Key input in both the add provider modal and the deploy
stepper's provider step.
* feat: navigate to deployments tab and open test modal after canvas deploy
After a successful deployment from the canvas deploy button, clicking
"Test" navigates to the deployments tab and auto-opens the test modal.
Also adds eye toggle to the deploy stepper's API Key field.
* Add llm config to deployment creation workflow
* [autofix.ci] apply automated fixes
* feat: add useGetDeploymentLlms query hook
Add missing query hook for the GET /deployments/llms endpoint,
resolving the broken import in step-type.tsx.
* Create provider env inline of step
Ensures the list llm call has an authed provider account to use
* feat: add extensibility for wxo tools in deployments api (#12425)
* feat(deployments): surface tool_ids in WXO API for explicit tool control
- Fix bind to reuse existing WXO tools via attachment lookup instead of
always creating new ones
- Add tool_id-based operations (bind_tool, unbind_tool, remove_tool_by_id)
alongside existing flow_version_id operations
- Add PATCH /deployments/snapshots/{provider_snapshot_id} endpoint to
update snapshot content with a new flow version (blast-radius bounded
to Langflow-tracked tools only)
- Add update_snapshot method to WXO adapter
- Enrich flow version list with deployment info (tool_id, tool_name,
app_ids) via FlowVersionReadWithDeployments API schema
- Surface tool_id in WatsonxApiToolAppBinding responses; flow_version_id
becomes optional for tool-id-based operations
* Revert "feat: Add Langflow Assistant chat panel for component generation (#11636)"
This reverts commit
|
|||
| 0b6269df6e |
docs: policies component (#12628)
cleanup-docs-and-add-to-sidebars-and-release-note |
|||
| f0f0681962 |
fix: handle read-only filesystem when updating starter project files (#12606)
* fix: handle read-only filesystem when updating starter project files (#11145)
When running Langflow in containerized environments with
readOnlyRootFilesystem: true, the update_project_file() function would
fail when trying to write updated project data back to the package
installation directory.
This fix catches OSError and logs it as debug instead of failing, since
the database is the source of truth for project data - file updates are
optional convenience for development environments.
Fixes #11145
* Update test_security_cors.py
* Revert "Update test_security_cors.py"
This reverts commit
|
|||
| 83f9b86d2a |
feat: watsonx Orchestrate deployment UI polish (#12621)
* feat: add credentials help link to deployment stepper and add-provider modal Add a descriptive hint below the watsonx Orchestrate provider card in both the deployment stepper and the add-provider modal, linking users to the IBM docs to find their credentials. * feat: add Beta badge to deployments tab and provider card * fix: keep provider selector visible when selected provider has no deployments The environment dropdown was hidden whenever deployments.length was 0, stranding users on the empty state with no way to switch providers. * feat: use watsonx Orchestrate logo in deployment provider UI Replaces the generic Bot icon with a dedicated WatsonxOrchestrate SVG in the deployment stepper and add-environment modal, wired through the existing IBM icon barrel and the eager/lazy icon registries. * fix: tighten Beta badge styling in main page header Constrain height, padding, font size and color so the Beta badge renders consistently alongside the tab label instead of inheriting oversized default sizing. * fix: rename "Deployment Providers" tab to "Deployment Environments" Aligns the sub-tab label with the environment-centric terminology introduced in #12551. |
|||
| 1ddea3a0ff | fix(models): Stop returning 'Custom' for Azure and Watsonx LLMs (#12608) | |||
| fc91e392d7 |
fix(mcp): Preserve nested dict arguments sent to MCP tools (#12601)
* fix msg dict on mcp server * add more test coverage * fix on input schema --------- Co-authored-by: Antônio Alexandre Borges Lima <104531655+AntonioABLima@users.noreply.github.com> |
|||
| 9dad1965c9 |
ci: add component index sync on label addition (#12590)
Add component index sync on label addition Adds a job that attempts to sync comp index with manual addition of label on PR |
|||
| 3077850fd5 |
fix: use startswith for safe path traversal and parsing (#12559)
* Fix use of path in flow helpers * use safe startswith for path construction |
|||
| 6585fe6617 |
fix: Remove ddl_if from session_metadata indexes in MessageTable (#12623)
The .ddl_if(dialect="postgresql") on the session_metadata indexes hides them from alembic's autogenerate metadata comparison. On PostgreSQL, the migration creates the indexes in the database but autogenerate doesn't see them in the model, so command.check() reports remove_index operations and the app crashes on startup. Removing ddl_if lets autogenerate see the indexes. The postgresql_using parameter already ensures they're only created on PostgreSQL. Verified: 1.8.1 -> 1.9.0 upgrade on PostgreSQL now works; SQLite is unaffected. |
|||
| 678da97976 |
fix: allow spacebar in chat input textarea (#12612)
fix: allow spacebar in chat input textarea |
|||
| 767c18bf3a |
docs: flow devops toolkit SDK manage multiple environments (#12479)
* flow-devops-sdk-basic-usage * multiple-environments |
|||
| 954bc8065d |
fix: Make sure we don't toggle models on hover (#12599)
* fix: Make sure we don't toggle models on hover * Revert to switch with stop prop event * global stopPropogation property for switches |
|||
| e245d05f62 |
docs: langflow assistant feature (#12439)
* initial-content * add-release-note * move-page-to-flows * fix-link-error * table-format * peer-review * sidebar-title * Apply suggestions from code review Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com> --------- Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com> |
|||
| cab9ba80da | fix: Add os catch error to prevent windows failure installation on desktop on lfx lazy import (#12617) | |||
| 296c148cbb |
fix: convert MCP image content to LangChain multimodal format (#12610)
* fix: convert MCP image content to LangChain multimodal format (#11812) When an MCP tool returns content of type 'image', Langflow was passing the raw CallToolResult object (as a Python string representation) to the LLM instead of a proper multimodal message. This meant vision-capable LLMs never received the actual image data in a format they could process. Adds _convert_mcp_result() and wires it into both the async (create_tool_coroutine) and sync (create_tool_func) execution paths. * [autofix.ci] apply automated fixes * test: add regression tests for _convert_mcp_result (#11812) Covers all cases of the new helper: - None / empty content → empty string - Text-only → plain string (backward compat) - Single image → image_url block list - Mixed text + image → ordered list - Missing mimeType → defaults to image/png - Multiple images → all converted * [autofix.ci] apply automated fixes * fix: convert MCP image content to LangChain multimodal format (#11812) Addresses reviewer feedback from PR #12610: [P1] Move conversion out of create_tool_coroutine/create_tool_func so mcp_component.py (line 685) still receives a raw CallToolResult via exec_tool.coroutine() directly. [P2] Avoid dropping structuredContent: ToolInvoker calls ainvoke without tool_call_id and continues to receive the raw CallToolResult. Defensive ToolMessage.artifact branch added for future-proofing. Conversion now happens only at the LangChain tool boundary inside MCPStructuredTool.run() / arun(), branching on tool_call_id: - tool_call_id absent → raw CallToolResult returned (programmatic callers) - tool_call_id present → tool_call_id is popped before super() to prevent BaseTool from stringifying the result (base.py:1272/1274), then a ToolMessage is returned with the converted multimodal content and the original CallToolResult preserved as artifact. Tests use update_tools() with a mocked stdio client to exercise the real MCPStructuredTool class instead of a local copy. Existing TestMCPStructuredTool fixture updated to stay in sync with the new run()/arun() logic. * [autofix.ci] apply automated fixes * fix: preserve unsupported MCP block types and fix ruff docstring - _convert_mcp_result() no longer silently drops resource, resource_link, audio, or any unknown block types. Unsupported blocks are serialised as {"type": "text", "text": json.dumps(block.model_dump())} so no content is lost on the agent path. Falls back to str(block) when model_dump() is unavailable. - Collapse-to-plain-string logic now triggers only when every block is plain text (not just when there are no images). - Fix D205/D209 ruff docstring violations in test_tool_invoker.py. - Add tests: resource-only result, mixed image+resource, unknown block without model_dump. * [autofix.ci] apply automated fixes * fix: Address lost tool call id after pop --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Eric Hare <ericrhare@gmail.com> |
|||
| 34886de048 |
fix: Updated Pillow minimum version (#12609)
* fix(frontend): enforce brace-expansion override * fix: enforce handlebars version >=4.7.9 in frontend overrides * fix: update Pillow minimum version to 12.1.1 --------- Co-authored-by: Janardan S Kavia <janardanskavia@Janardans-MacBook-Pro.local> |
|||
| adc94310e7 |
fix: add message table indexes for PostgreSQL to model (#12572)
* add index to model identical to the migration ef4b036b585d * add line * test(alembic): remove stale message index diff suppression The message session_metadata expression indexes are now defined in SQLModel metadata. Remove the old Postgres-only suppression so migration checks can surface real index drift. --------- Co-authored-by: Himavarsha <40851462+HimavarshaVS@users.noreply.github.com> |