Files
langflow/docs
Jordan Frazier 1707415a85 fix(security): clarify connector SSRF errors and document hardening toggles
Address PR-review findings on the connector SSRF wrapper and docs:
- validate_connector_url_for_ssrf: raise a clear, actionable error for a
  scheme-less / host-less connector URL (e.g. Milvus "host:19530") instead
  of the shared validator's confusing "Invalid URL scheme ''". The message
  tells the operator to use an explicit http(s) scheme and notes that
  allowlisting alone does not permit a scheme-less host (the format gate
  runs before the allowlist check). Only fires when host validation would
  actually run (global SSRF on); stays a no-op otherwise.
- Document the DNS-rebinding residual in the wrapper docstring: connectors
  hand the URL to third-party clients that re-resolve DNS at connect time
  and expose no pinned-IP hook (would break TLS SNI), so unlike api_request
  this guard is validate-then-connect. Literal-IP targets (metadata,
  RFC1918) are blocked identically.
- Docs: add a "Multi-tenant component hardening" section covering
  LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS and
  LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS, recommended alongside
  LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false.
- Tests: add TestConnectorURLValidation (disabled no-op, metadata blocked,
  scheme-less clear-error, no-op when global SSRF off).
2026-06-16 13:16:31 -04:00
..
2025-02-06 17:44:46 +00:00

Website

This website is built using Docusaurus 3, a modern static website generator.

Installation

$ npm install

Local Development

$ npm run start

This command starts a local development server and opens up a browser window. Most changes are reflected live without having to restart the server.

Build

$ npm run build

This command generates static content into the build directory and can be served using any static contents hosting service, including npm run serve.

Import code snippets from the repo

To embed source files directly in the docs, use raw-loader to import the file as a string and pass it to the native CodeBlock component.

import CodeBlock from "@theme/CodeBlock";
import customComponent from "!!raw-loader!@langflow/src/lfx/src/lfx/custom/custom_component/custom_component.py";

<CodeBlock language="python" title="CustomComponent metadata (from codebase)">
  {customComponent}
</CodeBlock>

Docusaurus Versioning

The versioning configuration is found in docusaurus.config.js.

Versioning example for release version 1.9.x on top of 1.8.x:

  1. Before release, the docs in the active release branch should already be set to 1.8.x, the current version.
  2. When ready to release 1.9.x, create a branch and run npm run docs:version -- 1.9.0 to snapshot the current docs.
  3. After creating a new version, update docusaurus.config.js to include the 1.9.0 release:
docs: {
  lastVersion: '1.9.0',
  versions: {
    '1.9.0': {
      label: '1.9.x',
      path: '1.9.0',
    },
    '1.8.0': {
      label: '1.8.x',
      path: '1.8.0',
    },
  },
},
  1. Test the deployment locally:
npm run build
npm run serve
  1. Create a pull request to main, and merge to create your new release.
  2. To create version 2.0.x, repeat the process: update the active release branch docs to 2.0.x when you begin working on it, then when ready to release, run npm run docs:version -- 2.0.0, update docusaurus.config.js with labels using .x notation, and merge to main.
  • lastVersion = the most recent released version (shown as "latest" in the UI).

See the Docusaurus docs for more info.

Disable versioning

  1. Remove the versions configuration from docusaurus.config.js.
  2. Delete the docs/versioned_docs/ and docs/versioned_sidebars/ directories.
  3. Delete docs/versions.json.

References

Deployment

Using SSH:

$ USE_SSH=true npm run deploy

Not using SSH:

$ GIT_USER=<Your GitHub username> npm run deploy

If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the gh-pages branch.