Eric Hare 4b0644f577 refactor(authz): split utils.py and address PR #13153 review
Address review feedback on the OSS authorization foundations PR:

- B1/I1: Split services/authorization/utils.py (694 lines, mixed
  responsibilities) into focused modules:
    - audit.py    — batched audit pipeline (audit_decision, writer loop)
    - guards.py   — ensure_*_permission family (collapsed via _RESOURCE_SPECS
                    registry; nine 25-line clones become 7 thin wrappers)
    - listing.py  — filter_visible_resources
  utils.py remains as a back-compat re-export shim so existing call sites
  (api/v1/flows.py, deployments.py, etc.) keep working untouched.

- B2: Split tests/unit/services/authorization/test_utils.py (1004 lines)
  into test_audit.py, test_guards.py, test_filter_visible.py,
  test_domain_resolution.py. Shared stubs + monkeypatch helpers extracted
  into _common.py; pytest fixtures into conftest.py.

- I2: ensure_permission default 403 detail is now "Permission denied" —
  callers can opt into a richer message via the new `detail=` kwarg. The
  previous default echoed flow:<uuid> in the response, leaking existence
  to non-owners on any route that forgot to wrap in deny_to_404.

- I4: Document the OSS floor contract on _ensure_can_administer_share —
  the early-return is dead in OSS (supports_cross_user_fetch() is False)
  and the explicit 403 is the actual floor; the enterprise plugin gates
  via the downstream ensure_share_permission call.

- R2: Audit drop logging is now time-based (first drop + at most every
  10s during persistent saturation) instead of every 1000th drop. Low
  drop rates no longer go minutes without a log line.

- R5: Seed migration's non-Postgres/SQLite fallback wraps the INSERT in
  a SAVEPOINT and swallows IntegrityError. Two concurrent migration
  runners can no longer race past the SELECT-then-INSERT check.

- R6: IntegrityError tests in test_authz_models.py now verify the
  *specific* constraint fired — column names for unique partial indexes
  (SQLite doesn't surface the index name), constraint name substring
  for CHECK constraints. A generic NOT NULL regression would no longer
  pass these tests.

All 180 authz tests pass; ruff clean.
2026-05-26 11:13:57 -07:00

Langflow logo

Release Notes PyPI - License PyPI - Downloads Twitter YouTube Channel Discord Server Ask DeepWiki

Langflow is a powerful platform for building and deploying AI-powered agents and workflows. It provides developers with both a visual authoring experience and built-in API and MCP servers that turn every workflow into a tool that can be integrated into applications built on any framework or stack. Langflow comes with batteries included and supports all major LLMs, vector databases and a growing library of AI tools.

Highlight features

  • Visual builder interface to quickly get started and iterate.
  • Source code access lets you customize any component using Python.
  • Interactive playground to immediately test and refine your flows with step-by-step control.
  • Multi-agent orchestration with conversation management and retrieval.
  • Deploy as an API or export as JSON for Python apps.
  • Deploy as an MCP server and turn your flows into tools for MCP clients.
  • Observability with LangSmith, LangFuse and other integrations.
  • Enterprise-ready security and scalability.

🖥️ Langflow Desktop

Langflow Desktop is the easiest way to get started with Langflow. All dependencies are included, so you don't need to manage Python environments or install packages manually. Available for Windows and macOS.

📥 Download Langflow Desktop

Quickstart

Requires Python 3.103.13 and uv (recommended package manager).

Install

From a fresh directory, run:

uv pip install langflow -U

The latest Langflow package is installed. For more information, see Install and run the Langflow OSS Python package.

Run

To start Langflow, run:

uv run langflow run

Langflow starts at http://127.0.0.1:7860.

That's it! You're ready to build with Langflow! 🎉

📦 Other install options

Run from source

If you've cloned this repository and want to contribute, run this command from the repository root:

make run_cli

For more information, see DEVELOPMENT.md.

Docker

Start a Langflow container with default settings:

docker run -p 7860:7860 langflowai/langflow:latest

Langflow is available at http://localhost:7860/. For configuration options, see the Docker deployment guide.

🛡️ Security

For security information, see our Security Policy.

🚀 Deployment

Langflow is completely open source and you can deploy it to all major deployment clouds. To learn how to deploy Langflow, see our Langflow deployment guides.

Stay up-to-date

Star Langflow on GitHub to be instantly notified of new releases.

Star Langflow

👋 Contribute

We welcome contributions from developers of all levels. If you'd like to contribute, please check our contributing guidelines and help make Langflow more accessible.


Star History Chart

❤️ Contributors

langflow contributors

Description
Langflow is a powerful tool for building and deploying AI-powered agents and workflows.
Readme MIT 2.3 GiB
Languages
Python 64.5%
TypeScript 23.4%
JavaScript 11.4%
CSS 0.3%
Makefile 0.2%
Other 0.1%