Skip to content

fix: Langflow logo on home page when s3 is enabled #10352

Merged
deon-sanchez merged 10 commits into
mainfrom
s3-storage-profile-pic
Nov 12, 2025
Merged

fix: Langflow logo on home page when s3 is enabled #10352
deon-sanchez merged 10 commits into
mainfrom
s3-storage-profile-pic

Conversation

@deon-sanchez
Copy link
Copy Markdown
Collaborator

@deon-sanchez deon-sanchez commented Oct 21, 2025

This pull request refactors the handling of profile pictures in the backend to always use the local filesystem for storing and serving profile images, regardless of the configured storage type (local, S3, etc.). It also adds comprehensive tests to verify profile picture listing and downloading, including error handling and content-type correctness.

Profile picture storage and retrieval (Backend changes):

  • Refactored the download_profile_picture and list_profile_pictures endpoints in src/backend/base/langflow/api/v1/files.py to access profile pictures directly from the local filesystem (config_dir/profile_pictures/) using async file operations, removing any dependency on the storage service or storage type configuration.
  • Added error handling to return a 404 if a requested profile picture file does not exist, and ensured correct content-type headers are set for SVG images.

Testing and validation (Unit tests):

  • Added a new pytest fixture (setup_profile_pictures) in src/backend/tests/unit/api/v1/test_files.py to set up a temporary profile pictures directory structure for tests, including sample SVG files for both "People" and "Space" folders.
  • Added multiple async test cases to verify:
    • Listing profile pictures returns expected files and formats.
    • Downloading profile pictures works and returns correct SVG content and content-type.
    • Non-existent profile picture requests return a 404 error.
    • Profile picture endpoints work correctly even when storage type is set to S3, confirming local-only handling.
    • Content-type headers for SVG files are correctly set for all profile pictures.

Summary by CodeRabbit

  • Bug Fixes

    • Improved profile picture retrieval with enhanced error handling and proper status codes for missing files.
  • Tests

    • Added comprehensive test coverage for profile picture listing and download operations, including error scenarios.

@deon-sanchez deon-sanchez self-assigned this Oct 21, 2025
@coderabbitai
Copy link
Copy Markdown
Contributor

coderabbitai Bot commented Oct 21, 2025

Walkthrough

The changes modify profile picture endpoints in the files API to read directly from local filesystem using a SettingsService dependency, replacing prior storage service integration. Two new dependencies are added, path construction is updated, and error handling is refined with 404/500 responses. Corresponding unit tests validate the new behavior including content-type handling and non-existent file scenarios.

Changes

Cohort / File(s) Summary
API endpoint updates
src/backend/base/langflow/api/v1/files.py
Modified download_profile_picture() and list_profile_pictures() endpoints to accept SettingsService dependency, read directly from local filesystem using async operations via anyio, construct paths from config_dir/profile_pictures/, and return 404 for missing files.
Test suite expansion
src/backend/tests/unit/api/v1/test_files.py
Added setup_profile_pictures fixture to configure temporary profile picture directories and environment overrides. Added 6 test cases covering listing, downloading, content-type validation, not-found scenarios, S3 storage compatibility, and file-type handling.

Sequence Diagram(s)

sequenceDiagram
    actor Client
    participant Endpoint as API Endpoint
    participant Settings as SettingsService
    participant FileSystem as Local FileSystem
    
    Note over Client,FileSystem: Download Profile Picture Flow
    Client->>Endpoint: GET /profile_pictures/{folder}/{file}
    Endpoint->>Settings: Get config_dir (via Depends)
    Settings-->>Endpoint: config_dir path
    Endpoint->>FileSystem: Read config_dir/profile_pictures/{folder}/{file}
    alt File exists
        FileSystem-->>Endpoint: File bytes
        Endpoint-->>Client: 200 + file content (image/svg+xml)
    else File not found
        FileSystem-->>Endpoint: Not found error
        Endpoint-->>Client: 404 Not Found
    else General error
        FileSystem-->>Endpoint: Exception
        Endpoint-->>Client: 500 Internal Server Error
    end
    
    Note over Client,FileSystem: List Profile Pictures Flow
    Client->>Endpoint: GET /profile_pictures
    Endpoint->>Settings: Get config_dir (via Depends)
    Settings-->>Endpoint: config_dir path
    Endpoint->>FileSystem: List config_dir/profile_pictures/People
    FileSystem-->>Endpoint: Files from People
    Endpoint->>FileSystem: List config_dir/profile_pictures/Space
    FileSystem-->>Endpoint: Files from Space
    Endpoint-->>Client: 200 + combined files list
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~22 minutes

Complexity factors: Dual endpoint modifications with dependency injection changes, async filesystem I/O patterns, error handling refinements, and a comprehensive test suite (1 fixture + 6 tests) covering multiple scenarios including edge cases and storage-type compatibility. Requires verification of path construction correctness, async operations behavior, and test coverage adequacy.

Pre-merge checks and finishing touches

❌ Failed checks (2 warnings, 1 inconclusive)
Check name Status Explanation Resolution
Test Quality And Coverage ⚠️ Warning The PR includes six profile picture tests that cover main functionality (listing, downloading), success cases (200 status, correct SVG content types), error cases (404 for missing files), cross-storage scenarios (S3 configuration), and content validation using proper async pytest patterns. However, the implementation contains a critical path traversal vulnerability: the download_profile_picture function constructs file paths directly from user-supplied folder_name and file_name parameters without any validation (no resolve(), realpath(), or path boundary checks), allowing attackers to use ../ sequences to access files outside the intended profile_pictures directory. The review comments explicitly requested three security tests to validate rejection of path traversal attempts, but these tests are completely absent from the test suite, leaving the vulnerability unvalidated and the API endpoint error response testing incomplete. The test suite must include the three path traversal security tests specified in the review comments: test_download_profile_picture_path_traversal_folder, test_download_profile_picture_path_traversal_filename, and test_download_profile_picture_invalid_folder. These tests should verify that requests with path traversal sequences (e.g., ../../../etc/passwd) and invalid folder names are rejected with 400 or 404 status codes. Additionally, the implementation should be updated to validate that resolved paths remain within the profile_pictures directory using Path.resolve() comparison and explicit folder name validation before constructing the file path.
Test File Naming And Structure ⚠️ Warning The test file test_files.py follows proper pytest naming conventions (test_*.py) with correct structure and async test functions having descriptive names that clearly explain what is being tested (e.g., test_download_profile_picture_space_rocket, test_download_profile_picture_not_found). Tests are logically organized with proper setup and teardown using the setup_profile_pictures fixture that creates temporary directories and performs cleanup. The test suite covers positive scenarios (successful downloads and listings), some negative scenarios (404 for missing files), and edge cases (S3 storage compatibility, content-type handling). However, the test suite fails to achieve comprehensive coverage by omitting critical security edge cases and error conditions: path traversal vulnerabilities in both folder and filename parameters, and invalid folder name validation, which are explicitly identified in the PR review comments as important security concerns. Add the three security tests specified in the review comments to complete the comprehensive coverage requirement: test_download_profile_picture_path_traversal_folder to test path traversal in the folder parameter, test_download_profile_picture_path_traversal_filename to test path traversal in the filename parameter, and test_download_profile_picture_invalid_folder to test rejection of invalid folder names. Each test should verify that the endpoint returns 400 or 404 status codes with appropriate error detail messages, ensuring both positive and negative scenarios including critical security edge cases are properly covered.
Test Coverage For New Implementations ❓ Inconclusive Based on the review comments provided with this PR, there is a clear requirement for security tests related to path traversal vulnerabilities in the profile picture endpoints. The review comment explicitly requests three specific tests: test_download_profile_picture_path_traversal_folder, test_download_profile_picture_path_traversal_filename, and test_download_profile_picture_invalid_folder. These tests are designed to verify that the endpoint properly rejects path traversal attempts (using ../ sequences) and invalid folder names with appropriate HTTP status codes (400 or 404). The PR summary shows that new tests were added for profile picture functionality including coverage for listing, downloading, and S3 storage compatibility, but the provided review comments indicate that critical security regression tests for path traversal prevention are missing. Path traversal attacks use "dot-dot-slash (../)" sequences to access files and directories stored outside the intended directory, making these security tests essential for validating the implementation. To complete this check, I need to verify whether the three path traversal security tests mentioned in the review comment have been implemented in the test file. Please run a search for these specific test function names in src/backend/tests/unit/api/v1/test_files.py to confirm whether they exist. If they do not exist, the PR is missing critical security test coverage for path traversal attacks. Additionally, verify that the implementation in src/backend/base/langflow/api/v1/files.py includes proper path validation using techniques like Path.resolve() and containment checks to ensure that accessed files remain within the intended profile pictures directory.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage ✅ Passed Docstring coverage is 90.00% which is sufficient. The required threshold is 80.00%.
Excessive Mock Usage Warning ✅ Passed The test suite demonstrates appropriate mock usage rather than excessive mocking. The fixtures create real objects (database entities, app instances, filesystem structures) and use monkeypatch only for environment configuration, which is a legitimate testing pattern. The tests avoid the anti-pattern of over-mocking filesystem operations or HTTP interactions, instead testing actual behavior through integration-style testing with real temporary resources. The setup_profile_pictures fixture creates actual SVG files in temporary directories rather than mocking filesystem operations, enabling tests to verify genuine file behavior. This design avoids brittle tests that would break with implementation changes while still maintaining isolation through temporary environments.
Title check ✅ Passed The title references fixing the Langflow logo on the home page when S3 is enabled, which directly aligns with the PR objective (#10352) about the logo being empty when LANGFLOW_STORAGE_TYPE=s3. The changes implement local filesystem-based profile picture retrieval that works independently of the storage backend.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch s3-storage-profile-pic

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@codecov
Copy link
Copy Markdown

codecov Bot commented Oct 21, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 31.66%. Comparing base (a56de93) to head (1a4e7a9).
⚠️ Report is 1 commits behind head on main.

❌ Your project status has failed because the head coverage (39.58%) is below the target coverage (60.00%). You can increase the head coverage or adjust the target coverage.

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main   #10352      +/-   ##
==========================================
+ Coverage   31.62%   31.66%   +0.03%     
==========================================
  Files        1330     1330              
  Lines       60407    60410       +3     
  Branches     9029     9029              
==========================================
+ Hits        19102    19126      +24     
+ Misses      40394    40374      -20     
+ Partials      911      910       -1     
Flag Coverage Δ
backend 51.38% <100.00%> (+0.13%) ⬆️
frontend 13.55% <ø> (ø)
lfx 39.58% <ø> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
src/backend/base/langflow/api/v1/files.py 66.14% <100.00%> (+16.94%) ⬆️

... and 1 file with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Copy link
Copy Markdown
Contributor

@coderabbitai coderabbitai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
src/backend/base/langflow/api/v1/files.py (1)

129-158: Critical: Validate folder_name and file_name to prevent path traversal attacks.

The function constructs file paths using user-supplied folder_name and file_name parameters without validation. An attacker could use path traversal sequences (e.g., ../../../etc/passwd) to access files outside the intended profile_pictures directory.

Apply these changes to add validation:

 async def download_profile_picture(
     folder_name: str,
     file_name: str,
     settings_service: Annotated[SettingsService, Depends(get_settings_service)],
 ):
     """Download profile picture from local filesystem.
 
     Profile pictures are always stored locally in config_dir/profile_pictures/,
     regardless of the storage_type setting (local, s3, etc.).
     """
     try:
+        # Validate folder_name to prevent path traversal
+        allowed_folders = {"People", "Space"}
+        if folder_name not in allowed_folders:
+            raise HTTPException(status_code=400, detail=f"Invalid folder name. Must be one of: {allowed_folders}")
+        
+        # Validate file_name to prevent path traversal
+        if ".." in file_name or "/" in file_name or "\\" in file_name:
+            raise HTTPException(status_code=400, detail="Invalid file name")
+        
         extension = file_name.split(".")[-1]
         config_dir = settings_service.settings.config_dir
         config_path = Path(config_dir)  # type: ignore[arg-type]
         file_path = config_path / "profile_pictures" / folder_name / file_name
+        
+        # Additional safety check: ensure resolved path is within profile_pictures
+        resolved_path = file_path.resolve()
+        expected_base = (config_path / "profile_pictures").resolve()
+        if not str(resolved_path).startswith(str(expected_base)):
+            raise HTTPException(status_code=400, detail="Invalid file path")
 
         if not file_path.exists():
             raise HTTPException(status_code=404, detail=f"Profile picture {folder_name}/{file_name} not found")
🧹 Nitpick comments (1)
src/backend/base/langflow/api/v1/files.py (1)

160-186: Consider using async filesystem operations for consistency.

The function uses synchronous filesystem operations (iterdir(), is_file()) despite being declared async. This is inconsistent with download_profile_picture which uses anyio.Path for async operations.

For consistency, consider refactoring to use async operations:

     """List profile pictures from local filesystem.
 
     Profile pictures are always stored locally in config_dir/profile_pictures/,
     regardless of the storage_type setting (local, s3, etc.).
     """
     try:
         config_dir = settings_service.settings.config_dir
         config_path = Path(config_dir)  # type: ignore[arg-type]
 
-        people_path = config_path / "profile_pictures" / "People"
-        space_path = config_path / "profile_pictures" / "Space"
+        people_path = anyio.Path(config_path / "profile_pictures" / "People")
+        space_path = anyio.Path(config_path / "profile_pictures" / "Space")
 
         # List files directly from local filesystem
-        people = [f.name for f in people_path.iterdir() if f.is_file()] if people_path.exists() else []
-        space = [f.name for f in space_path.iterdir() if f.is_file()] if space_path.exists() else []
+        people = []
+        if await people_path.exists():
+            async for f in people_path.iterdir():
+                if await f.is_file():
+                    people.append(f.name)
+        
+        space = []
+        if await space_path.exists():
+            async for f in space_path.iterdir():
+                if await f.is_file():
+                    space.append(f.name)
 
     except Exception as e:
         raise HTTPException(status_code=500, detail=str(e)) from e
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between cea4b42 and 6adc58d.

📒 Files selected for processing (2)
  • src/backend/base/langflow/api/v1/files.py (2 hunks)
  • src/backend/tests/unit/api/v1/test_files.py (1 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
{src/backend/**/*.py,tests/**/*.py,Makefile}

📄 CodeRabbit inference engine (.cursor/rules/backend_development.mdc)

{src/backend/**/*.py,tests/**/*.py,Makefile}: Run make format_backend to format Python code before linting or committing changes
Run make lint to perform linting checks on backend Python code

Files:

  • src/backend/base/langflow/api/v1/files.py
  • src/backend/tests/unit/api/v1/test_files.py
src/backend/tests/unit/**/*.py

📄 CodeRabbit inference engine (.cursor/rules/backend_development.mdc)

Test component integration within flows using create_flow, build_flow, and get_build_events utilities

Files:

  • src/backend/tests/unit/api/v1/test_files.py
src/backend/tests/**/*.py

📄 CodeRabbit inference engine (.cursor/rules/testing.mdc)

src/backend/tests/**/*.py: Unit tests for backend code must be located in the 'src/backend/tests/' directory, with component tests organized by component subdirectory under 'src/backend/tests/unit/components/'.
Test files should use the same filename as the component under test, with an appropriate test prefix or suffix (e.g., 'my_component.py' → 'test_my_component.py').
Use the 'client' fixture (an async httpx.AsyncClient) for API tests in backend Python tests, as defined in 'src/backend/tests/conftest.py'.
When writing component tests, inherit from the appropriate base class in 'src/backend/tests/base.py' (ComponentTestBase, ComponentTestBaseWithClient, or ComponentTestBaseWithoutClient) and provide the required fixtures: 'component_class', 'default_kwargs', and 'file_names_mapping'.
Each test in backend Python test files should have a clear docstring explaining its purpose, and complex setups or mocks should be well-commented.
Test both sync and async code paths in backend Python tests, using '@pytest.mark.asyncio' for async tests.
Mock external dependencies appropriately in backend Python tests to isolate unit tests from external services.
Test error handling and edge cases in backend Python tests, including using 'pytest.raises' and asserting error messages.
Validate input/output behavior and test component initialization and configuration in backend Python tests.
Use the 'no_blockbuster' pytest marker to skip the blockbuster plugin in tests when necessary.
Be aware of ContextVar propagation in async tests; test both direct event loop execution and 'asyncio.to_thread' scenarios to ensure proper context isolation.
Test error handling by mocking internal functions using monkeypatch in backend Python tests.
Test resource cleanup in backend Python tests by using fixtures that ensure proper initialization and cleanup of resources.
Test timeout and performance constraints in backend Python tests using 'asyncio.wait_for' and timing assertions.
Test Langflow's Messag...

Files:

  • src/backend/tests/unit/api/v1/test_files.py
**/{test_*.py,*.test.ts,*.test.tsx}

📄 CodeRabbit inference engine (coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt)

**/{test_*.py,*.test.ts,*.test.tsx}: Review test files for excessive use of mocks that obscure what's actually being tested
Warn when mocks replace testing of real behavior and interactions
Suggest using real objects or simpler test doubles when mocks become excessive
Ensure mocks are reserved for external dependencies, not core logic
Recommend integration tests when unit tests are overly mocked
Test files should have descriptive test function names that explain what is being tested
Organize tests logically with proper setup and teardown
Include edge cases and error conditions for comprehensive coverage
Verify tests cover both positive and negative scenarios where appropriate
Tests should cover the main functionality being implemented
Tests should not be mere smoke tests; they must assert and validate behavior

Files:

  • src/backend/tests/unit/api/v1/test_files.py
**/{test_*.py,*.test.ts}

📄 CodeRabbit inference engine (coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt)

Check that test files follow naming conventions: backend test_*.py, frontend *.test.ts

Files:

  • src/backend/tests/unit/api/v1/test_files.py
**/test_*.py

📄 CodeRabbit inference engine (coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt)

**/test_*.py: Backend tests must be named test_*.py and use proper pytest structure
For async Python code, ensure proper async testing patterns with pytest (e.g., async fixtures, event loop)
Backend tests should follow project patterns: use pytest for test execution and structure
For API endpoints, verify tests cover both success and error responses

Files:

  • src/backend/tests/unit/api/v1/test_files.py
🧬 Code graph analysis (1)
src/backend/base/langflow/api/v1/files.py (3)
src/backend/tests/unit/api/v2/test_mcp_servers_file.py (1)
  • settings_service (96-97)
src/backend/base/langflow/services/deps.py (1)
  • get_settings_service (122-135)
src/lfx/src/lfx/utils/helpers.py (1)
  • build_content_type_from_extension (33-34)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (16)
  • GitHub Check: Lint Backend / Run Mypy (3.13)
  • GitHub Check: Lint Backend / Run Mypy (3.11)
  • GitHub Check: Run Frontend Tests / Determine Test Suites and Shard Distribution
  • GitHub Check: Lint Backend / Run Mypy (3.10)
  • GitHub Check: Lint Backend / Run Mypy (3.12)
  • GitHub Check: Run Backend Tests / Unit Tests - Python 3.10 - Group 2
  • GitHub Check: Run Backend Tests / Unit Tests - Python 3.10 - Group 5
  • GitHub Check: Run Backend Tests / Unit Tests - Python 3.10 - Group 1
  • GitHub Check: Run Backend Tests / Unit Tests - Python 3.10 - Group 4
  • GitHub Check: Run Backend Tests / Unit Tests - Python 3.10 - Group 3
  • GitHub Check: Run Backend Tests / Test CLI - Python 3.10
  • GitHub Check: Run Backend Tests / LFX Tests - Python 3.10
  • GitHub Check: Run Backend Tests / Integration Tests - Python 3.10
  • GitHub Check: Test Starter Templates
  • GitHub Check: Update Component Index
  • GitHub Check: Optimize new Python code in this PR
🔇 Additional comments (8)
src/backend/base/langflow/api/v1/files.py (1)

9-9: LGTM: Import added for async filesystem operations.

The anyio import is correctly added to support async file operations used later in the file.

src/backend/tests/unit/api/v1/test_files.py (7)

290-323: LGTM: Well-structured test fixture.

The fixture properly sets up a temporary directory with profile pictures, overrides the config directory, and ensures cleanup. The dependency on files_client ensures proper initialization ordering.


326-349: LGTM: Comprehensive test for listing profile pictures.

The test properly verifies the response structure, checks for expected folder prefixes, and validates that specific files are present. The docstring clearly explains the test's purpose.


352-370: LGTM: Thorough test for downloading profile pictures.

The test validates the HTTP response, content-type header, and SVG content structure. Good coverage of the download functionality.


373-406: LGTM: Defensive test with proper edge case handling.

The test handles the case where no people profile pictures are available by using pytest.skip, which is the correct approach. The verification of content-type and SVG structure is thorough.


409-420: LGTM: Good test coverage for 404 error case.

The test properly validates that requesting a non-existent file returns a 404 status code and includes an appropriate error message.


423-448: Excellent test for the PR objective!

This test directly validates the fix for the issue described in the PR title. It confirms that profile pictures are served from the local filesystem even when LANGFLOW_STORAGE_TYPE=s3, which is exactly what this PR aims to fix.


451-475: LGTM: Good coverage of content-type handling.

The test validates that SVG files are served with the correct image/svg+xml content-type for both Space and People folders.


assert response.status_code == 413, f"Expected 413, got {response.status_code}: {response.json()}"
assert "Content size limit exceeded. Maximum allowed is 1MB and got 1.001MB." in response.json()["detail"]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion | 🟠 Major

Add tests for path traversal security vulnerabilities.

The test suite should include tests that verify the endpoint properly rejects path traversal attempts. This is especially important given the security vulnerability identified in the implementation.

Add these security tests:

async def test_download_profile_picture_path_traversal_folder(files_client, setup_profile_pictures):  # noqa: ARG001
    """Test that path traversal in folder_name is rejected.
    
    Args:
        files_client: HTTP client for making API requests
        setup_profile_pictures: Fixture that sets up profile pictures directory
    """
    # Try to access a file outside the profile_pictures directory
    response = await files_client.get("api/v1/files/profile_pictures/../../../etc/passwd")
    assert response.status_code in [400, 404], "Should reject path traversal attempts"


async def test_download_profile_picture_path_traversal_filename(files_client, setup_profile_pictures):  # noqa: ARG001
    """Test that path traversal in file_name is rejected.
    
    Args:
        files_client: HTTP client for making API requests
        setup_profile_pictures: Fixture that sets up profile pictures directory
    """
    # Try to access a file using path traversal in filename
    response = await files_client.get("api/v1/files/profile_pictures/Space/../../../etc/passwd")
    assert response.status_code in [400, 404], "Should reject path traversal attempts"


async def test_download_profile_picture_invalid_folder(files_client, setup_profile_pictures):  # noqa: ARG001
    """Test that invalid folder names are rejected.
    
    Args:
        files_client: HTTP client for making API requests
        setup_profile_pictures: Fixture that sets up profile pictures directory
    """
    response = await files_client.get("api/v1/files/profile_pictures/InvalidFolder/test.svg")
    assert response.status_code == 400, "Should reject invalid folder names"
    assert "Invalid folder name" in response.json()["detail"]
🤖 Prompt for AI Agents
In src/backend/tests/unit/api/v1/test_files.py around line 288, add unit tests
that assert the profile picture download endpoint rejects path traversal and
invalid folder names: create three async tests—one that requests
"api/v1/files/profile_pictures/../../../etc/passwd" and asserts status_code in
[400, 404]; one that requests
"api/v1/files/profile_pictures/Space/../../../etc/passwd" and asserts
status_code in [400, 404]; and one that requests
"api/v1/files/profile_pictures/InvalidFolder/test.svg" and asserts status_code
== 400 and that the response JSON detail contains "Invalid folder name"—use the
existing files_client and setup_profile_pictures fixtures and include brief
docstrings as in the review comment.

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Oct 23, 2025

Frontend Unit Test Coverage Report

Coverage Summary

Lines Statements Branches Functions
Coverage: 15%
14.65% (3957/26993) 7.45% (1533/20566) 8.99% (532/5916)

Unit Test Results

Tests Skipped Failures Errors Time
1588 0 💤 0 ❌ 0 🔥 18.935s ⏱️

@Adam-Aghili
Copy link
Copy Markdown
Collaborator

@deon-sanchez how would I test this PR?

Copy link
Copy Markdown
Collaborator

@lucaseduoli lucaseduoli left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@deon-sanchez deon-sanchez added lgtm This PR has been approved by a maintainer fix Bug fixes and patches labels Nov 12, 2025
@deon-sanchez deon-sanchez added lgtm This PR has been approved by a maintainer and removed lgtm This PR has been approved by a maintainer labels Nov 12, 2025
@deon-sanchez deon-sanchez changed the title Langflow logo on home page is empty when LANGFLOW_STORAGE_TYPE=s3 fix: Langflow logo on home page is empty when LANGFLOW_STORAGE_TYPE=s3 Nov 12, 2025
@deon-sanchez deon-sanchez changed the title fix: Langflow logo on home page is empty when LANGFLOW_STORAGE_TYPE=s3 fix: Langflow logo on home page when s3 is enabled Nov 12, 2025
@github-actions github-actions Bot added bug Something isn't working and removed bug Something isn't working labels Nov 12, 2025
@deon-sanchez deon-sanchez added this pull request to the merge queue Nov 12, 2025
@deon-sanchez deon-sanchez removed this pull request from the merge queue due to a manual request Nov 12, 2025
@deon-sanchez deon-sanchez added this pull request to the merge queue Nov 12, 2025
Merged via the queue into main with commit 586c79d Nov 12, 2025
212 of 216 checks passed
@deon-sanchez deon-sanchez deleted the s3-storage-profile-pic branch November 12, 2025 22:25
Kabilan-16 added a commit to SaravanakumarR2018/DragDropAIAgentBuilder that referenced this pull request Jan 21, 2026
* docs: Improve README Quickstart section and add dark mode logo (#10358)

* Improve README Quickstart section and reorganize installation options

- Add prominent Desktop download section before Quickstart
- Remove $ symbols from shell commands to fix copy button functionality
- Add clear 'Run from source' option with make run_cli for developers
- Improve Docker installation instructions with usage details
- Move security warnings to after installation options for better flow
- Remove redundant star/issues badges

These changes address common user confusion when trying to run Langflow,
especially for developers who clone the repo first and then struggle with
the package installation instructions.

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>

* Add dark mode logo support

- Added picture element for automatic dark/light mode logo switching
- Dark mode shows blue background logo, light mode shows black logo

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>

* Final README improvements

- Made 'Other install options' a proper section with emoji
- Updated deployment section with rocket emoji
- Fixed single-line formatting for subsections
- Added new star animation gif
- Changed 'tool' to 'platform' in description

* Improve Desktop download section messaging

- Made text more concise and action-oriented
- Changed download emoji from arrow to inbox
- Removed redundant 'built-in' and bold formatting
- Cleaner parenthetical for OS availability

* Revise README for Langflow Desktop and deployment info

Updated sections for clarity and added details about Langflow Desktop and deployment options.

* Revert star gif to GitHub attachment URL

Testing if local file path issue or markdown previewer issue

* Apply suggestion from @mendonk

* Apply suggestion from @mendonk

* Apply suggestion from @mendonk

* Apply suggestion from @mendonk

* readme-changes

* Apply suggestion from @mendonk

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Mendon Kissling <59585235+mendonk@users.noreply.github.com>
Co-authored-by: Gabriel Luiz Freitas Almeida <gabriel@langflow.org>

* fix: require active user for monitor endpoints (#10568)

Require active user for monitor endpoints

* refactor: Reorganize sidebar categories (#10180)

* Reorganize sidebar categories

* finishing touches

* templates

* ruff check fix

* merge fix

* filter out knowledge when ff'd off

* BE tests

* [autofix.ci] apply automated fixes

* more test fixes

* integration test fix

* Unit tests

* more test fixes

* reorg tests

* [autofix.ci] apply automated fixes

* update ui tests

* [autofix.ci] apply automated fixes

* mcp and playwright tests

* [autofix.ci] apply automated fixes

* BE test fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* test fix

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Edwin Jose <edwin.jose@datastax.com>

* fix(agent): handle missing message id for disconnected agents (#10560)

* fix(agent): handle missing message id for disconnected agents

* [autofix.ci] apply automated fixes

* will this update comp index

* comp index

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Jordan Frazier <jordan.frazier@datastax.com>

* fix: Langflow logo on home page when s3 is enabled  (#10352)

* fixed and added tests

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* fix(playground): preserve timer start time when playground is reopened (#10516)

* Fix playground timer

* add jest unit tests

---------

Co-authored-by: cristhianzl <cristhian.lousa@gmail.com>

* fix: MCP component auto reset issue in non Tool Mode (#10440)

* Optimize tool dropdown handling and output processing

Improves logic for updating tool dropdown options by checking if the server has changed and whether tool mode is active, reducing unnecessary updates. Adds a process_output_item method to parse tool output as JSON when appropriate, enhancing output handling.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* Update component_index.json

* Update Nvidia Remix.json

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Update component_index.json

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* use cache enabled even for the no tool mode

* Update component_index.json

* [autofix.ci] apply automated fixes

* Update Nvidia Remix.json

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* Add Notion integration components to index

Updated component_index.json to include new Notion integration components: AddContentToPage, NotionDatabaseProperties, NotionListPages, NotionPageContent, NotionPageCreator, NotionPageUpdate, and NotionSearch. These components provide functionality for interacting with Notion databases and pages, including querying, creating, updating, and retrieving content.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* fix: add selector to let dropdown load

add Select a tool selector to let dropdown load before interacting

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Update MCPToolsComponent code and metadata

Updated the code and code_hash for MCPToolsComponent in Nvidia Remix starter project and synchronized the component_index.json to reflect the latest code and metadata. This ensures consistency and includes recent improvements or fixes to the MCPToolsComponent implementation.

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Adam Aghili <Adam.Aghili@ibm.com>

* fix: Switch to browser-compatible MathJax import (#10563)

add browser support to rehype package build

* feat: patch icons to support dark theme and Composio Slack component fix. (#10577)

* feat: add Composio Components & logos tweak

* Display name consistency

* update init

* fix: format

* fix: suggested changes by Mike

* feat: add Composio Components & logos tweak

* Display name consistency

* update init

* fix: format

* fix: suggested changes by Mike

* updates components JSON

* fix: format

* updates components JSON

* Remove unnecessary blank lines in __init__.py

Cleaned up formatting by deleting extra blank lines in the _dynamic_imports dictionary for improved readability.

* Update component_index.json

* Update component_index.json

* Update component_index.json

* Update component_index.json

* fix: Slack component issue

* fix: icons update to support dark theme

* fix: Klaviyo imports

* Update component_index.json

---------

Co-authored-by: Edwin Jose <edwin.jose@datastax.com>

* feat: add toolkit_versions and updated composio and composio_langchain versions. (#10578)

* feat: added toolkit versions and updated composio and composio_langchain packages

* fix: format

---------

Co-authored-by: Edwin Jose <edwin.jose@datastax.com>

* fix: marked required fields for fields with MultilineInput input types. (#10579)

fix: marked required fields with MultilineInputs

Co-authored-by: Edwin Jose <edwin.jose@datastax.com>

* feat: replaced initiate method with link method. (#10580)

feat: replaced .initiate() with .link()

Co-authored-by: Edwin Jose <edwin.jose@datastax.com>

* feat: Add ALTK Agent with tool validation and comprehensive tests (#10587)

* Add ALTK Agent with tool validation and comprehensive tests

- Added agent-lifecycle-toolkit~=0.4.1 dependency to pyproject.toml
- Implemented ALTKBaseAgent with comprehensive error handling and tool validation
- Added ALTKToolWrappers for SPARC integration and tool execution safety
- Created ALTK Agent component with proper LangChain integration
- Added comprehensive test suite covering tool validation, conversation context, and edge cases
- Fixed docstring formatting to comply with ruff linting standards

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* minor fix to execute_tool that was left out.

* Fixes following coderabbitai comments.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* Update component_index.json

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Add custom message to dict conversion in ValidatedTool

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Add Notion integration components to index

Updated component_index.json to include new Notion integration components: AddContentToPage, NotionDatabaseProperties, NotionListPages, NotionPageContent, NotionPageCreator, NotionPageUpdate, and NotionSearch. These components provide functionality for interacting with Notion databases and pages, including querying, creating, updating, and retrieving content.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

---------

Co-authored-by: Koren Lazar <koren.lazar@ibm.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Edwin Jose <edwin.jose@datastax.com>

* feat: Add MCP server config sanitization for sensitive data (#10552)

add clean mcp config function

* feat: Implement dynamic model discovery system (#10523)

* add dynamic model request

* add description to groq

* add cache folder to store cache models json

* change git ignore description

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* add comprehensive tests for Groq dynamic model discovery

- Add 101 unit tests covering success, error, and edge cases
- Test model discovery, caching, tool calling detection
- Test fallback models and backward compatibility
- Add support for real GROQ_API_KEY from environment
- Fix all lint errors and improve code quality

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* fix Python 3.10 compatibility - replace UTC with timezone.utc

Python 3.10 doesn't have datetime.UTC, need to use timezone.utc instead

* fix pytest hook signature - use config instead of _config

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* fix conftest config.py

* fix timezone UTC on tests

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* feat: remove `code` from Transactions to reduce clutter in logs (#10400)

* refactor: remove code from transaction model inputs

* refactor: remove code from transaction model inputs

* tests: add tests to make sure code is not added to transactions data

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* refactor: improve code removal from logs with explicit dict copying

---------

Co-authored-by: Edwin Jose <edwin.jose@datastax.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* refactor(service_manager): implement lazy initalization of service manager (#8828)

* refactor: implement lazy initialization for ServiceManager with thread safety

- Replaced direct instantiation of ServiceManager with a lazy initialization approach using a global variable and threading lock.
- Updated the public API to expose `get_service_manager` for retrieving the singleton instance.
- Ensured thread-safe access to the ServiceManager instance to prevent issues during module import.

* refactor: update service manager imports to use get_service_manager

- Replaced direct imports of service_manager with get_service_manager in multiple files to ensure consistent access to the singleton instance.
- This change enhances code clarity and maintains the lazy initialization approach for the ServiceManager.

* refactor: remove deprecated Enhanced ServiceManager implementation

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* refactor: implement thread-safe lazy initialization for ServiceManager

* feat: add filelock dependency in lfx

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* update component index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* feat: new release for cuga component (#10591)

* feat: new release of cuga

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* fix: address review

* fix: fixed more bugs

* fix: build component index

* [autofix.ci] apply automated fixes

* fix: update test

* chore: update component index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* ci: upgrade playwright to 1.56 and fix second time imports (#10284)

* chore: update Playwright and related dependencies to version 1.56.0 in package.json and package-lock.json

* refactor: update addLegacyComponents function to improve selector checks

- Replaced the expect assertion with a waitForSelector call to ensure the sidebar legacy switch is checked, enhancing reliability in tests.
- Updated import statement for Page from "@playwright/test" for consistency with current practices.

* fix playwright imports

* chore: update Playwright version in CI workflow to 1.56.0 for consistency with project dependencies

* refactor: enhance lockFlow and unlockFlow functions for improved visibility checks

- Replaced isVisible calls with waitFor to ensure elements are visible before proceeding, enhancing test reliability.
- Removed unnecessary waitForTimeout calls to streamline the flow execution process.

* test(playwright): add validation for settings menu header text

* refactor(playwright): improve lock flow test with expect assertions

* refactor(playwright): simplify legacy component toggle validation

* feat: adds Component Inputs telemetry (#10254)

* feat: Introduce telemetry tracking for sensitive field types

Added a new set of field types that should not be tracked in telemetry due to their sensitive nature, including PASSWORD, AUTH, FILE, CONNECTION, and MCP. Updated relevant input classes to ensure telemetry tracking is disabled for these sensitive fields, enhancing data privacy and security.

* feat: Enhance telemetry payloads with additional fields and serialization support

Added new fields to the ComponentPayload and ComponentInputsPayload classes, including component_id and component_run_id, to improve telemetry data tracking. Introduced a serialize_input_values function to handle JSON serialization of component input values, ensuring robust handling of input data for telemetry purposes.

* feat: Implement telemetry input tracking and caching

Added functionality to track and cache telemetry input values within the Component class. Introduced a method to determine if inputs should be tracked based on sensitivity and an accessor for retrieving cached telemetry data, enhancing the robustness of telemetry handling.

* feat: Add logging for component input telemetry

Introduced a new method, log_package_component_inputs, to the TelemetryService for logging telemetry data related to component inputs. This enhancement improves the tracking capabilities of the telemetry system, allowing for more detailed insights into component interactions.

* feat: Enhance telemetry logging for component execution

Added functionality to log component input telemetry both during successful execution and error cases. Introduced a unique component_run_id for each execution to improve tracking. This update ensures comprehensive telemetry data collection, enhancing the robustness of the telemetry system.

* feat: Extend telemetry payload tests and enhance serialization

Added tests for the new component_id and component_run_id fields in ComponentPayload and ComponentInputsPayload classes. Introduced a new test suite for ComponentInputTelemetry, covering serialization of various data types and handling of edge cases. This update improves the robustness and coverage of telemetry data handling in the system.

* fix: Update default telemetry tracking behavior in BaseInputMixin

Changed the default value of track_in_telemetry from True to False in the BaseInputMixin class. Updated documentation to clarify that telemetry tracking is now opt-in and can be explicitly enabled for individual input types, enhancing data privacy and control.

* fix: Update telemetry tracking defaults for input types

Modified the default value of `track_in_telemetry` for various input classes to enhance data privacy. Regular inputs now default to False, while safe inputs like `IntInput` and `BoolInput` default to True, ensuring explicit opt-in for telemetry tracking. Updated related tests to reflect these changes.

* feat: add chunk_index and total_chunks fields to ComponentInputsPayload

This commit adds two new optional fields to ComponentInputsPayload:
- chunk_index: Index of this chunk in a split payload sequence
- total_chunks: Total number of chunks in the split sequence

Both fields default to None and use camelCase aliases for serialization.
This is Task 1 of the telemetry query parameter splitting implementation.

Tests included:
- Verify fields exist and can be set
- Verify camelCase serialization aliases work correctly
- Verify fields default to None when not provided

Generated with Claude Code (https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* refactor: update ComponentInputsPayload to support automatic splitting of oversized inputs

This commit enhances the ComponentInputsPayload class by implementing functionality to automatically split input values into multiple chunks if they exceed the maximum URL size limit. Key changes include:

- Added methods for calculating URL size, truncating oversized values, and splitting payloads.
- Updated component_inputs field to accept a dictionary instead of a string for better handling of input values.
- Improved documentation for the ComponentInputsPayload class to reflect the new splitting behavior and usage examples.

These changes aim to improve telemetry data handling and ensure compliance with URL length restrictions.

* refactor: enhance log_package_component_inputs to handle oversized payloads

This commit updates the log_package_component_inputs method in the TelemetryService class to split component input payloads into multiple requests if they exceed the maximum URL size limit. Key changes include:

- Added logic to split the payload using the new split_if_needed method.
- Each chunk is queued separately for telemetry logging.

These improvements ensure better handling of telemetry data while adhering to URL length restrictions.

* refactor: centralize maximum telemetry URL size constant

This commit introduces a centralized constant, MAX_TELEMETRY_URL_SIZE, to define the maximum URL length for telemetry GET requests. Key changes include:

- Added MAX_TELEMETRY_URL_SIZE constant to schema.py for better maintainability.
- Updated split_if_needed method in ComponentInputsPayload to use the new constant instead of a hardcoded value.
- Adjusted the TelemetryService to reference the centralized constant for URL size limits.

These changes enhance code clarity and ensure consistent handling of URL size limits across the telemetry service.

* refactor: update ComponentInputsPayload tests to use dictionary inputs

This commit modifies the tests for ComponentInputsPayload to utilize a dictionary for component inputs instead of a serialized JSON string. Key changes include:

- Renamed the test method to reflect the new input type.
- Removed unnecessary serialization steps and assertions related to JSON strings.
- Added assertions to verify the correct handling of dictionary inputs.

These changes streamline the testing process and improve clarity in how component inputs are represented.

* test: add integration tests for telemetry service payload splitting

This commit introduces integration tests for the TelemetryService to verify its handling of large and small payloads. Key changes include:

- Added tests to ensure large payloads are split into multiple chunks and queued correctly.
- Implemented a test to confirm that small payloads are not split and result in a single queued event.
- Created a mock settings service for testing purposes.

These tests enhance the reliability of the telemetry service by ensuring proper payload management.

* test: enhance ComponentInputsPayload tests with additional scenarios

This commit expands the test suite for ComponentInputsPayload by adding various scenarios to ensure robust handling of input payloads. Key changes include:

- Introduced tests for calculating URL size, ensuring it returns a positive integer and accounts for encoding.
- Added tests to verify the splitting logic for large payloads, including checks for chunk metadata and preservation of fixed fields.
- Implemented property-based tests using Hypothesis to validate that all chunks respect the maximum URL size and preserve original data.

These enhancements improve the reliability and coverage of the ComponentInputsPayload tests, ensuring proper functionality under various conditions.

* [autofix.ci] apply automated fixes

* optimize query param encoding

Co-authored-by: codeflash-ai[bot] <148906541+codeflash-ai[bot]@users.noreply.github.com>

* refactor: extract telemetry logging logic into a separate function

This commit introduces a new function, _log_component_input_telemetry, to centralize the logic for logging component input telemetry. The function is called in two places within the generate_flow_events function, improving code readability and maintainability by reducing duplication. This change enhances the clarity of telemetry handling in the flow generation process.

* refactor: optimize truncation logic in ComponentInputsPayload

This commit refines the truncation logic for input values in the ComponentInputsPayload class. The previous binary search method for string values has been simplified, allowing for direct truncation of both string and non-string values. This change enhances code clarity and maintains functionality while ensuring optimal handling of oversized inputs.

* refactor: update telemetry tracking logic to respect opt-in flag

This commit modifies the telemetry tracking logic in the Component class to change the default behavior of the `track_in_telemetry` attribute from True to False. This adjustment enhances user privacy by requiring explicit consent for tracking input objects in telemetry. The change ensures that sensitive field types are still auto-excluded from tracking, maintaining the integrity of the telemetry data.

* refactor: update tests to use dictionary format for component inputs

This commit modifies the integration tests for telemetry payload validation and component input telemetry to utilize dictionaries for component inputs instead of serialized JSON strings. Key changes include:

- Updated assertions to compare dictionary inputs directly.
- Enhanced clarity and maintainability of the test cases by removing unnecessary serialization steps.

These changes improve the representation of component inputs in tests, aligning with recent refactoring efforts.

* [autofix.ci] apply automated fixes

* refactor: specify type for current_chunk_inputs in ComponentInputsPayload

This commit updates the type annotation for the current_chunk_inputs variable in the ComponentInputsPayload class to explicitly define it as a dictionary. This change enhances code clarity and maintainability by providing better type information for developers working with the code.

* test: add component_id to ComponentPayload tests

This commit enhances the test cases for the ComponentPayload class by adding a component_id parameter to various initialization tests. The updates ensure that the component_id is properly tested across different scenarios, including valid parameters, error messages, and edge cases. This change improves the robustness of the tests and aligns with recent updates to the ComponentPayload structure.

* [autofix.ci] apply automated fixes

* feat: add component_id to ComponentPayload in build_vertex function

* fix: update MAX_TELEMETRY_URL_SIZE to 2048 and adjust related tests

This commit increases the maximum URL size for telemetry GET requests from 2000 to 2048 bytes to align with Scarf's specifications. Corresponding test assertions have been updated to reference the new constant, ensuring consistency across the codebase.

* [autofix.ci] apply automated fixes

* feat(telemetry): add track_in_telemetry field to starter project configurations

* refactor(telemetry): remove unused blank line in test imports

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* update starter templates

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: codeflash-ai[bot] <148906541+codeflash-ai[bot]@users.noreply.github.com>

* fix(telemetry): resolve cyclic import in telemetry service (#10598)

* fix(telemetry): resolve cyclic import by moving get_email_model

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* feat: Add gpt-5.1 model to Language models (#10590)

* Add gpt-5.1 model to starter projects

Added 'gpt-5.1' to the list of available models in all starter project JSON files to support the new model version. This update ensures users can select gpt-5.1 in agent configurations.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Update component_index.json

* [autofix.ci] apply automated fixes

* Update component_index.json

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* fix: Use the proper Embeddings import for Qdrant vector store (#10613)

* Use the proper Embeddings import for Qdrant vector store

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------

Co-authored-by: Madhavan <cxo@ibm.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* fix: Ensure split text test is more robust (#10622)

* fix: Ensure split text test is more robust

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* docs: security notice (#10555)

* docs-security-notice

* Apply suggestions from code review

Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>

* code-review

* link-to-security-bulletin

* Apply suggestions from code review

Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>

---------

Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>

* fix: use issubclass in the pool creation (#10232)

* use issubclass in the pool creation

* [autofix.ci] apply automated fixes

* add poolclass pytests

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------

Co-authored-by: Hamza Rashid <74062092+HzaRashid@users.noreply.github.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: cristhianzl <cristhian.lousa@gmail.com>

* docs: OpenAPI spec version upgraded from 1.6.5 to 1.6.8 (#10627)

Co-authored-by: github-merge-queue <118344674+github-merge-queue@users.noreply.github.com>
Co-authored-by: Mendon Kissling <59585235+mendonk@users.noreply.github.com>

* chore: Fix indentation on bundles-docling.mdx (#10640)

* feat: make it possible to load graphs using `get_graph` function in scripts (#9913)

* feat: Enhance graph loading functionality to support async retrieval

- Updated `load_graph_from_script` to be an async function, allowing for the retrieval of the graph via an async `get_graph` function if available.
- Implemented fallback to the existing `graph` variable for backward compatibility.
- Enhanced `find_graph_variable` to identify both `get_graph` function definitions and `graph` variable assignments, improving flexibility in script handling.

* feat: Update load_graph_from_script to support async graph retrieval

- Refactored `load_graph_from_script` to be an async function, enabling the use of an async `get_graph` function for graph retrieval.
- Implemented a fallback mechanism to access the `graph` variable for backward compatibility.
- Enhanced error handling to provide clearer messages when neither `graph` nor `get_graph()` is found in the script.

* feat: Refactor simple_agent.py to support async graph creation

- Introduced an async `get_graph` function to handle the initialization of components and graph creation without blocking.
- Updated the logging configuration and component setup to be part of the async function, improving the overall flow and responsiveness.
- Enhanced documentation for the `get_graph` function to clarify its purpose and return type.

* feat: Update serve_command and run functions to support async graph loading

- Refactored `serve_command` to be an async function using `syncify`, allowing for non-blocking execution.
- Updated calls to `load_graph_from_path` and `load_graph_from_script` within `serve_command` and `run` to await their results, enhancing performance and responsiveness.
- Improved overall async handling in the CLI commands for better integration with async workflows.

* feat: Refactor load_graph_from_path to support async execution

- Changed `load_graph_from_path` to an async function, enabling non-blocking graph loading.
- Updated the call to `load_graph_from_script` to use await, improving performance during graph retrieval.
- Enhanced the overall async handling in the CLI for better integration with async workflows.

* feat: Enhance async handling in simple_agent and related tests

- Updated `get_graph` function in `simple_agent.py` to utilize async component initialization for improved responsiveness.
- Modified test cases in `test_simple_agent_in_lfx_run.py` to validate the async behavior of `get_graph`.
- Refactored various test functions across multiple files to support async execution, ensuring compatibility with the new async workflows.
- Improved documentation for async functions to clarify their purpose and usage.

* docs: Implement async get_graph function for improved component initialization

- Introduced an async `get_graph` function in `README.md` to facilitate non-blocking component initialization.
- Enhanced the logging configuration and component setup within the async function, ensuring a smoother flow.
- Updated documentation to clarify the purpose and return type of the `get_graph` function, aligning with the async handling improvements.

* refactor: reorder imports in simple_agent test file

* style: reorder imports in simple_agent test file

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* update component index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* feat: Add custom download node function (#10659)

* add custom download node

* use download node

* feat: Add type check before issubclass in service discovery (#10636)

* Add type check before issubclass in service discovery

Added an isinstance(obj, type) check before issubclass to prevent errors when inspecting module members for Service and ServiceFactory subclasses. This improves robustness when dynamically importing services and factories.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* docs: readme update  (#10657)

* dep-management

* are

* fix: minor redesign of guardrails for disabling components in LF Astra cloud (#10662)

* create cloud validation util file

disable local_db if in astra cloud

disable split_video if in astra cloud

disable video_file component if in astra cloud

ruff (video_file.py)

correct the error message in video_file.py

disable mem0 and composio in astra cloud

update astra disable component util fn name to be more descriptive

add tests for disabling components

minor docs patch

remove component disable check in places that interact with building the component index

replace init test with execution in composio unit test suite

remove dotenv from validate_cloud

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* fix: prevent autofix workflow loop from bot commits (#10673)

fix(ci): prevent autofix workflow loop from bot commits

* fix(lfx-dev): reload specific modules while preserving index cache (#10629)

* fix(lfx-dev): reload specific modules while preserving index cache

* refactor: restructure component loading with strategy pattern for dev mode

* fix: improve cache loading error handling in component index loading

* refactor: reorganize CUGA and ALTK components into single-element bundles (#10671)

* moved cuga and altk

* reverted starter templates

* [autofix.ci] apply automated fixes

* updated import

* [autofix.ci] apply automated fixes

* revert starter templates

* fixed some python tests

* fix: update import assertions for backward compatibility in dynamic import tests

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* fix: update import paths for set_advanced_true and get_parent_agent_inputs in test_helper_functions

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* feat: fix cuga component with new release (#10646)

* bufix(cuga_agent): fixed no output chat bug

* fix: remove structured output feature

* fix: stablize component

* fix: chat output component not working

* fix: add strategy flag

* fix: update cuga version

* feat: add component index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* update some imports to use lfx

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* fix: update review

* chore: build component index

* chore: build component

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* fix(cuga): ensure message id exists when not connected to output

* fix: component result id on chat output

* chore: fix component index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Revert test_agent_component.py back to origin/main

* fix: remove unwanted tests

* chore: new build index

* [autofix.ci] apply automated fixes

* fix: update test

* chore: build index

* [autofix.ci] apply automated fixes

* fix: update package of cuga

* chore: build component index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* update comp index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* trying comp index again?

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

---------

Co-authored-by: Offer Akrabi <offer.akrabi@il.ibm.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Jordan Frazier <jordan.frazier@datastax.com>

* fix: Add IBM watsonx.ai support to EmbeddingModel (#10677)

* Add IBM watsonx.ai support to EmbeddingModel

Added IBM watsonx.ai as a supported provider in EmbeddingModelComponent, updated dependencies and code to integrate ibm_watsonx_ai and pydantic. Updated starter project and component index metadata to reflect new dependencies and code changes.

* update watsonx default models

* update index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Update test_embedding_model_component.py

* Update component_index.json

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* fix: rename LLM router to LLM selector (#10650)

* fix: rename LLM router to LLM selector

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* fix: rename LLMRouter component to LLMSelector

* fix: resolved merge conflicts

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* fix: resolved merge conflicts

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* fix: refactor file name

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* fix: resolve merge conflict

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* fix: resolve merge conflict

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* Fix: add environment variable flag to log alembic to stdout (#10620)

* fix: add flag to log alembic to stdout

fix indentation

refine docs

mypy (db service.py)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* fix: move sql database to data source category (#10651)

* fix: move sql database to data source category

* [autofix.ci] apply automated fixes

* fix: resolve merge conflict

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* fix: fixes YouTube Icon name in lazyloadingMapping (#10628)

* fix lazyloadingMapping component name

* fix: merge conflicts

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes

* fix: resolve merge conflict

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* Fix: rename sidebar category flow controls to flow control (#10649)

* rename sidebar category flow controls to flow control

* fix: addressed PR comments

* fix: expose logger functions at module level for backwards comp (#10670)

* Expose logger functions at module level for backwards comp

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* feat: agentic UX (#10567)

* Add empty __init__.py files for agentic modules

Created empty __init__.py files in agentic, core, tools, and utils directories to initialize them as Python packages.

* Add agentic template search utilities and tests

Introduces a new agentic utilities module for Langflow, including template search, tag extraction, and template count functions. Adds a README, demo script, and comprehensive unit tests for template search functionality.

* Add Langflow Agentic MCP server with FastMCP tools

Introduces a new MCP (Model Context Protocol) server for Langflow agentic tools using FastMCP. Adds server, CLI, example usage, tests, and comprehensive documentation. Exposes four MCP tools: search_templates, get_template, list_all_tags, and count_templates, enabling AI assistants to query and filter Langflow templates programmatically.

* Handle unparameterized list types in schema inputs

Adds support for unparameterized list annotations by treating them as lists of strings when converting schemas to Langflow inputs. This ensures nullable array schemas without explicit item types are handled gracefully.

* Refactor search_templates to simplify parameters

Removed the 'tags' parameter from the search_templates function and set a default value for 'fields'. Updated the call to list_templates to match the new signature, streamlining template search functionality.

* Add output item processing for tool results

Introduced process_output_item to handle tool output items, attempting to parse text-type items as JSON. This improves downstream handling of tool outputs by converting JSON strings to dictionaries when possible.

* Refactor knowledge base path initialization

Replaces direct settings access with a lazy-loading function for the knowledge bases root path in Knowledge Ingestion and Knowledge Retrieval starter projects. This improves reliability and consistency when accessing the knowledge base directory, and updates all usages to the new helper function.

* Update component_index.json

* Add IBM watsonx.ai support to starter projects

Introduces IBM watsonx.ai as a selectable model provider in multiple starter project JSONs. Adds new input fields for 'base_url', 'project_id', and 'max_output_tokens' to support IBM watsonx.ai integration. Updates agent component code to handle new provider and its required parameters.

* Add Ollama to supported LLM providers in starter projects

Ollama has been added as a supported provider alongside Anthropic, Google Generative AI, OpenAI, and IBM watsonx.ai in all starter project JSON files. This expands the available options for LLM integration in initial setup templates.

* Update Ollama model input constants and logic

Refactored model_input_constants.py to update the OLLAMA_MODEL_INPUTS and OLLAMA_MODEL_INPUTS_MAP. Modified ollama.py to use the new input mapping and improved input handling for Ollama components.

* Add flow creation from template MCP tool

Introduces a new MCP tool for creating flows from starter templates in Langflow Agentic. Adds the utility function `create_flow_from_template_and_get_link` and exposes it via the FastMCP server, allowing users to create flows by template id and receive a UI link. Updates imports and documentation accordingly.

* Add component search utilities and MCP tools to server

Introduces new component search and retrieval tools to the MCP server, including endpoints for searching, listing, and counting components. Adds support functions in support.py for data normalization and a new component_search.py utility module. Updates the Nvidia Remix starter project to use the latest MCPToolsComponent code.

* Add flow graph visualization utilities

Introduces async utility functions for generating ASCII and text representations of flow graphs, as well as metadata summaries. These utilities support fetching flows by ID or name, error handling, and integration with Langflow's graph and logging modules.

* Add flow component operations utilities and MCP tools

Introduces flow component management utilities in `flow_component.py` for retrieving, updating, and listing component field values. Exposes new MCP tools in `server.py` for accessing component details, field values, updating fields, and listing all fields within a flow component.

* Add SystemMessageGen flow and update MCPTools

Introduces SystemMessageGen.json flow for agentic system message generation and updates MCPTools component logic in flow_component.py to support new flow structure and tool handling.

* feat: init aiButton

create an aiButton that opens the prompt modal for demoing
add multiinput mixin

* Update component_index.json

* Refactor SystemMessageGen flow and remove unused init files

Updated SystemMessageGen.json to support custom instructions, OpenAI model configuration, and improved agent settings. Removed unused __init__.py files from agentic, core, tools, and utils directories to clean up the codebase.

* update to the mcp component

* Add verify_ssl option to MCPToolsComponent

Introduces a 'verify_ssl' boolean input to MCPToolsComponent for controlling SSL certificate verification in HTTPS connections. The option is added to the server config if not present, allowing users to disable verification for development or testing with self-signed certificates.

* Optimize tool dropdown handling and output processing

Improves logic for updating tool dropdown options by checking if the server has changed and whether tool mode is active, reducing unnecessary updates. Adds a process_output_item method to parse tool output as JSON when appropriate, enhancing output handling.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* feat: init onclick assistant prompt generation

first pass at on button click generate input and auto fill a field

* Replace MCPTools with Prompt Template in SystemMessageGen flow

Updated the SystemMessageGen.json flow to use the Prompt Template and Parser components instead of MCPTools. Adjusted edges, nodes, and component configurations to reflect the new prompt-based workflow, removing tool selection and execution logic in favor of prompt generation and parsing.

* Update SystemMessageGen flow and frontend dependencies

Refactored edge connections and metadata in SystemMessageGen.json to improve flow logic and updated endpoint name. Added new optional and peer dependencies to package-lock.json, including @mapbox/node-pre-gyp and related packages, to support canvas and other modules.

* Update user authentication in simplified_run_flow endpoint

Replaces the dependency on api_key_security with CurrentActiveUser for the api_key_user parameter in the simplified_run_flow endpoint. This change is part of a TODO to create a new endpoint and may affect how user authentication is handled.

* feat: hook everything up and have onclick prompt

hook up commit

* Add auto-configuration for Agentic MCP server

Introduces utilities and startup logic to automatically configure the Langflow Agentic MCP server for all users when the agentic experience is enabled. Adds a new settings flag `agentic_experience` to control this feature, and updates the main server startup to trigger configuration. This enables agentic tools for flow/component operations, template search, and graph visualization in MCP clients.

* Enable agentic MCP server and improve initialization

Set agentic_experience to True by default in settings. Refactor agentic MCP server initialization in main.py to run in the background with a delay and retry logic, improving startup reliability. Update function calls to use 'current_user' instead of 'user' in agentic_mcp.py for consistency.

* Update user authentication in simplified_run_flow

Modified the api_key_user parameter to accept either CurrentActiveUser or UserRead from api_key_security, supporting both Bearer and session authentication methods.

* revert the apikeu_user changes

* test new api endpoint

* Refactor agent flow and update component inputs

Updated SystemMessageGen.json to refactor edge connections and node IDs for agentic flow. Added 'base_url' as a required input, enabled 'ai_enabled' for agent description, and replaced static memory input handling with dynamic retrieval via get_base_inputs(). Also improved tool callback setup and updated code hash and last_updated metadata.

* Improve agentic flow creation and updating logic

Enhances the agentic flow setup to extract flow_id and endpoint_name from JSON, update existing flows by ID or endpoint_name, and create new flows if they don't exist. Adds detailed logging and ensures flows are up-to-date in the user's Langflow Assistant folder.

* chore: aibutton clean up

* chore: add assistant store

* Update SystemMessageGen.json

* Update agentic_mcp.py

* Update component_index.json

* Fix agent input extraction from Message objects

Agents now correctly extract and use the text content from Message objects, rather than passing the entire object or its string representation. This resolves issues where agents received verbose message representations instead of just the intended string input, and includes improved handling for multimodal content. Corresponding unit and integration tests have been added to verify this behavior for both OpenAI and Anthropic agents.

* Add TemplateAssistant Langflow flow definition

Introduces TemplateAssistant.json, a comprehensive Langflow flow configuration for agentic workflows. This flow integrates AstraDB, MCP Tools, and user input/output nodes, enabling document ingestion, search, and tool orchestration within the Langflow backend.

* Improve MCPToolsComponent server/tool config refresh

Refactored MCPToolsComponent to better handle tool and server config refreshes, especially when the MCP server changes. Added logic to avoid unnecessary clearing of tool inputs and options, and improved caching and UI update behavior for tool selection. Also updated related flow and starter project JSON files to reflect these changes.

* auto add Global Variables for Agentic Experience

* chore: clean up and get button working again

* cleanup .md

* fix:ruff, Refactor agentic utils and improve error handling

Introduces shared default field lists for template/component search, refactors exception handling to use logger and add finally/else blocks, and improves type hinting with TYPE_CHECKING. Updates file opening to use Path objects, enhances error logging in template search, and removes the unused test_template_search.py file.

* fix:ruff Expand exception handling in agentic MCP utilities

Broadened exception handling in agentic MCP server and variable management functions to catch specific errors such as HTTPException, SQLAlchemyError, and common system exceptions. This improves robustness and error logging during server configuration, removal, and variable initialization.

* aka-clean-up-1

* Remove duplicate process_output_item method

Deleted two redundant definitions of the process_output_item method from MCPToolsComponent to clean up the code and prevent confusion.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes

* Refactor service usage and improve project deletion logging

Refactored login API to reuse a single settings service instance. Enhanced logging and error messaging when attempting to delete the Langflow Assistant folder. Minor variable usage cleanup in agentic flows setup and agent component test.

* [autofix.ci] apply automated fixes (attempt 2/3)

* Update test_template_search.py

* Handle specific exceptions in agentic flow loading

Updated the exception handling in load_agentic_flows to catch only OSError and orjson.JSONDecodeError instead of all exceptions, improving error specificity and logging.

* Update component_index.json

* [autofix.ci] apply automated fixes

* revert loading setting service

* Update login.py

* Update SystemMessageGen.json

* Update TemplateAssistant.json

* [autofix.ci] apply automated fixes

* Update constants.py

* chore: seperate templateassistant and sysmessgen

seperate templateassistant and sysmessgen frontend queries

* chore: add header feature flag

* use feature flag for all ui

* [autofix.ci] apply automated fixes

* package-lcok update

* [autofix.ci] apply automated fixes

* chore: LANGFLOW_AGENTIC_EXPERIENCE fe ff name

* Update login.py

* lint fix

* [autofix.ci] apply automated fixes

* Update component_index.json

* chore: fix adjust-screan-view click

* chore: same force issue as adjust-screen-view

* chore: playwright pass 2

* revert package-lock

* add type to langflow_modules

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* Handle TypeError in class-based serialization

Adds a try-except block to catch TypeError when checking issubclass for objects that are types but not proper classes, such as typing special forms. This prevents serialization errors for generic aliases and similar constructs.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* Refactor type handling in field update and serialization

Changed 'new_value' parameter type to str in update_flow_component_field for stricter typing. Simplified exception handling in serialize by removing unnecessary try/except around issubclass checks for class-based Pydantic types.

---------

Co-authored-by: Adam Aghili <Adam.Aghili@ibm.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* ci: bump actions/checkout to v6 (#10697)

* feat: Improve OAuth error handling and frontend sync behavior (#10626)

* updates for version comp

* migrate mcp composer fix to main

* migrate mcp composer fix to main

* version constraints

* go back to pydantic 2.11

* remove logging

* directly pin to new version

* add instant feedback on error

* improve callback function behavior ux

* fix tests and mypy issues

* bump mcp composer version

* fixed latest version mcp

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* revert pydantic changes

* computed models pydantic fix

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------

Co-authored-by: Jordan Frazier <jordan.frazier@datastax.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Hamza Rashid <hzarashid@gmail.com>

* fix: Fix TypeError when LANGFLOW_ENABLE_LOG_RETRIEVAL is enabled (#10681)

* fix serialize issue when LANGFLOW_ENABLE_LOG_RETRIEVAL is true

* add logger tests

* [autofix.ci] apply automated fixes

* add multiple buffer checker

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* use serialize instead

* [autofix.ci] apply automated fixes

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Edwin Jose <edwin.jose@datastax.com>

* docs: update component documentation links to individual pages

* Revert "docs: update component documentation links to individual pages"

This reverts commit 1da51d4ccba9458506da6ff5b1ab7af23f09c2b6.

* test: catch import errors upfront (#10632)

* Convert to async and ruff-friendly print

* Implement the checking into existing test file itself

* Remove the newly introduced lfx test which is now incorporated into existing tests

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Run make build_component_index after merging latest from main

* [autofix.ci] apply automated fixes

* Revert "docs: update component documentation links to individual pages"

This reverts commit 1da51d4ccba9458506da6ff5b1ab7af23f09c2b6.

* build component index after origin/main merge into feature branch

* [autofix.ci] apply automated fixes

---------

Co-authored-by: Madhavan <cxo@ibm.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Mendon Kissling <59585235+mendonk@users.noreply.github.com>

* feat: Support appending files when saving (#10631)

* feat: Support appending files when saving

* Update save_file.py

* Update News Aggregator.json

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Update save_file.py

* Update save_file.py

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes

* Overwrite existing file if append mode is true

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Update test_mcp_servers_file.py

* [autofix.ci] apply automated fixes

* Update save_file.py

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>

* chore: Update pip and setuptools version constraints (#10708)

* update setuptools and pip

* remove from lfx pypoetry

* feat: Display node name in download error message (#10707)

add component name on download error

* feat: Add Message Support for Input of Loop Component (#10160)

* feat: Add support for messages in Loop Component

* feat: Add Message support for input of Loop Component

* [autofix.ci] apply automated fixes

* Update src/frontend/src/utils/reactflowUtils.ts

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* [autofix.ci] apply automated fixes

* More cleanup of looping

* Fix ruff errors

* [autofix.ci] apply automated fixes

* Update loop-component.spec.ts

* Make loop types generic

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Fixes from gabriel review

* [autofix.ci] apply automated fixes

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: Gabriel Luiz Freitas Almeida <gabriel@langflow.org>

* fix: Support tool mode in File Component properly (#10520)

* Support tool mode in dynamic outputs

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Tool mode and ruff fixes

* Template updates

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Update test_mcp_servers_file.py

* Revert "Update test_mcp_servers_file.py"

This reverts commit 25f24d0d8aa5a7c95c913f862d86513749195ad1.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* add possibility for the agent to access the processed output file

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: cristhianzl <cristhian.lousa@gmail.com>
Co-authored-by: Carlos Coelho <80289056+carlosrcoelho@users.noreply.github.com>

* docs: include regex for sanitized input types (#10712)

include-regex-for-sanitized-input

* feat: Version 1.2 - comprehensive database migration guidelines using… (#10519)

* feat: Version 1.2 - comprehensive database migration guidelines using the Expand-Contract pattern

* Update src/backend/base/langflow/alembic/DB-MIGRATION-GUIDE.MD

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* fix: Cleanup text and typos

* feat: Implement migration validation workflow and add migration validator scripts

* Update src/backend/base/langflow/alembic/migration_validator.py

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update src/backend/base/langflow/alembic/migration_validator.py

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update src/backend/base/langflow/alembic/migration_validator.py

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* fix: moved the test_migrations directory to under tests

* feat: Added migration validator to pre-commit check.

* fix: improved test performance.

* fix: optimized attribute resolution in migration validator

* feat: add comprehensive tests for migration validator and guidelines

* fix: Lint is complaining about shebang declared but not being used.

* fix: Shebang reinstated.

* Update src/backend/base/langflow/alembic/DB-MIGRATION-GUIDE.MD

Co-authored-by: Copilot <175728472+Copilot@users.…
SaravanakumarR2018 pushed a commit to SaravanakumarR2018/DragDropAIAgentBuilder that referenced this pull request Jan 22, 2026
* docs: Improve README Quickstart section and add dark mode logo (#10358)

* Improve README Quickstart section and reorganize installation options

- Add prominent Desktop download section before Quickstart
- Remove $ symbols from shell commands to fix copy button functionality
- Add clear 'Run from source' option with make run_cli for developers
- Improve Docker installation instructions with usage details
- Move security warnings to after installation options for better flow
- Remove redundant star/issues badges

These changes address common user confusion when trying to run Langflow,
especially for developers who clone the repo first and then struggle with
the package installation instructions.

🤖 Generated with [Claude Code](https://claude.ai/code)



* Add dark mode logo support

- Added picture element for automatic dark/light mode logo switching
- Dark mode shows blue background logo, light mode shows black logo

🤖 Generated with [Claude Code](https://claude.ai/code)



* Final README improvements

- Made 'Other install options' a proper section with emoji
- Updated deployment section with rocket emoji
- Fixed single-line formatting for subsections
- Added new star animation gif
- Changed 'tool' to 'platform' in description

* Improve Desktop download section messaging

- Made text more concise and action-oriented
- Changed download emoji from arrow to inbox
- Removed redundant 'built-in' and bold formatting
- Cleaner parenthetical for OS availability

* Revise README for Langflow Desktop and deployment info

Updated sections for clarity and added details about Langflow Desktop and deployment options.

* Revert star gif to GitHub attachment URL

Testing if local file path issue or markdown previewer issue

* Apply suggestion from @mendonk

* Apply suggestion from @mendonk

* Apply suggestion from @mendonk

* Apply suggestion from @mendonk

* readme-changes

* Apply suggestion from @mendonk

---------





* fix: require active user for monitor endpoints (#10568)

Require active user for monitor endpoints

* refactor: Reorganize sidebar categories (#10180)

* Reorganize sidebar categories

* finishing touches

* templates

* ruff check fix

* merge fix

* filter out knowledge when ff'd off

* BE tests

* [autofix.ci] apply automated fixes

* more test fixes

* integration test fix

* Unit tests

* more test fixes

* reorg tests

* [autofix.ci] apply automated fixes

* update ui tests

* [autofix.ci] apply automated fixes

* mcp and playwright tests

* [autofix.ci] apply automated fixes

* BE test fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* test fix

---------




* fix(agent): handle missing message id for disconnected agents (#10560)

* fix(agent): handle missing message id for disconnected agents

* [autofix.ci] apply automated fixes

* will this update comp index

* comp index

---------




* fix: Langflow logo on home page when s3 is enabled  (#10352)

* fixed and added tests

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------



* fix(playground): preserve timer start time when playground is reopened (#10516)

* Fix playground timer

* add jest unit tests

---------



* fix: MCP component auto reset issue in non Tool Mode (#10440)

* Optimize tool dropdown handling and output processing

Improves logic for updating tool dropdown options by checking if the server has changed and whether tool mode is active, reducing unnecessary updates. Adds a process_output_item method to parse tool output as JSON when appropriate, enhancing output handling.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* Update component_index.json

* Update Nvidia Remix.json

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Update component_index.json

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* use cache enabled even for the no tool mode

* Update component_index.json

* [autofix.ci] apply automated fixes

* Update Nvidia Remix.json

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* Add Notion integration components to index

Updated component_index.json to include new Notion integration components: AddContentToPage, NotionDatabaseProperties, NotionListPages, NotionPageContent, NotionPageCreator, NotionPageUpdate, and NotionSearch. These components provide functionality for interacting with Notion databases and pages, including querying, creating, updating, and retrieving content.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* fix: add selector to let dropdown load

add Select a tool selector to let dropdown load before interacting

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Update MCPToolsComponent code and metadata

Updated the code and code_hash for MCPToolsComponent in Nvidia Remix starter project and synchronized the component_index.json to reflect the latest code and metadata. This ensures consistency and includes recent improvements or fixes to the MCPToolsComponent implementation.

---------




* fix: Switch to browser-compatible MathJax import (#10563)

add browser support to rehype package build

* feat: patch icons to support dark theme and Composio Slack component fix. (#10577)

* feat: add Composio Components & logos tweak

* Display name consistency

* update init

* fix: format

* fix: suggested changes by Mike

* feat: add Composio Components & logos tweak

* Display name consistency

* update init

* fix: format

* fix: suggested changes by Mike

* updates components JSON

* fix: format

* updates components JSON

* Remove unnecessary blank lines in __init__.py

Cleaned up formatting by deleting extra blank lines in the _dynamic_imports dictionary for improved readability.

* Update component_index.json

* Update component_index.json

* Update component_index.json

* Update component_index.json

* fix: Slack component issue

* fix: icons update to support dark theme

* fix: Klaviyo imports

* Update component_index.json

---------



* feat: add toolkit_versions and updated composio and composio_langchain versions. (#10578)

* feat: added toolkit versions and updated composio and composio_langchain packages

* fix: format

---------



* fix: marked required fields for fields with MultilineInput input types. (#10579)

fix: marked required fields with MultilineInputs



* feat: replaced initiate method with link method. (#10580)

feat: replaced .initiate() with .link()



* feat: Add ALTK Agent with tool validation and comprehensive tests (#10587)

* Add ALTK Agent with tool validation and comprehensive tests

- Added agent-lifecycle-toolkit~=0.4.1 dependency to pyproject.toml
- Implemented ALTKBaseAgent with comprehensive error handling and tool validation
- Added ALTKToolWrappers for SPARC integration and tool execution safety
- Created ALTK Agent component with proper LangChain integration
- Added comprehensive test suite covering tool validation, conversation context, and edge cases
- Fixed docstring formatting to comply with ruff linting standards

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* minor fix to execute_tool that was left out.

* Fixes following coderabbitai comments.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* Update component_index.json

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Add custom message to dict conversion in ValidatedTool

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Add Notion integration components to index

Updated component_index.json to include new Notion integration components: AddContentToPage, NotionDatabaseProperties, NotionListPages, NotionPageContent, NotionPageCreator, NotionPageUpdate, and NotionSearch. These components provide functionality for interacting with Notion databases and pages, including querying, creating, updating, and retrieving content.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

---------





* feat: Add MCP server config sanitization for sensitive data (#10552)

add clean mcp config function

* feat: Implement dynamic model discovery system (#10523)

* add dynamic model request

* add description to groq

* add cache folder to store cache models json

* change git ignore description

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* add comprehensive tests for Groq dynamic model discovery

- Add 101 unit tests covering success, error, and edge cases
- Test model discovery, caching, tool calling detection
- Test fallback models and backward compatibility
- Add support for real GROQ_API_KEY from environment
- Fix all lint errors and improve code quality

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* fix Python 3.10 compatibility - replace UTC with timezone.utc

Python 3.10 doesn't have datetime.UTC, need to use timezone.utc instead

* fix pytest hook signature - use config instead of _config

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* fix conftest config.py

* fix timezone UTC on tests

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

---------



* feat: remove `code` from Transactions to reduce clutter in logs (#10400)

* refactor: remove code from transaction model inputs

* refactor: remove code from transaction model inputs

* tests: add tests to make sure code is not added to transactions data

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* refactor: improve code removal from logs with explicit dict copying

---------




* refactor(service_manager): implement lazy initalization of service manager (#8828)

* refactor: implement lazy initialization for ServiceManager with thread safety

- Replaced direct instantiation of ServiceManager with a lazy initialization approach using a global variable and threading lock.
- Updated the public API to expose `get_service_manager` for retrieving the singleton instance.
- Ensured thread-safe access to the ServiceManager instance to prevent issues during module import.

* refactor: update service manager imports to use get_service_manager

- Replaced direct imports of service_manager with get_service_manager in multiple files to ensure consistent access to the singleton instance.
- This change enhances code clarity and maintains the lazy initialization approach for the ServiceManager.

* refactor: remove deprecated Enhanced ServiceManager implementation

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* refactor: implement thread-safe lazy initialization for ServiceManager

* feat: add filelock dependency in lfx

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* update component index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------



* feat: new release for cuga component (#10591)

* feat: new release of cuga

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* fix: address review

* fix: fixed more bugs

* fix: build component index

* [autofix.ci] apply automated fixes

* fix: update test

* chore: update component index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------



* ci: upgrade playwright to 1.56 and fix second time imports (#10284)

* chore: update Playwright and related dependencies to version 1.56.0 in package.json and package-lock.json

* refactor: update addLegacyComponents function to improve selector checks

- Replaced the expect assertion with a waitForSelector call to ensure the sidebar legacy switch is checked, enhancing reliability in tests.
- Updated import statement for Page from "@playwright/test" for consistency with current practices.

* fix playwright imports

* chore: update Playwright version in CI workflow to 1.56.0 for consistency with project dependencies

* refactor: enhance lockFlow and unlockFlow functions for improved visibility checks

- Replaced isVisible calls with waitFor to ensure elements are visible before proceeding, enhancing test reliability.
- Removed unnecessary waitForTimeout calls to streamline the flow execution process.

* test(playwright): add validation for settings menu header text

* refactor(playwright): improve lock flow test with expect assertions

* refactor(playwright): simplify legacy component toggle validation

* feat: adds Component Inputs telemetry (#10254)

* feat: Introduce telemetry tracking for sensitive field types

Added a new set of field types that should not be tracked in telemetry due to their sensitive nature, including PASSWORD, AUTH, FILE, CONNECTION, and MCP. Updated relevant input classes to ensure telemetry tracking is disabled for these sensitive fields, enhancing data privacy and security.

* feat: Enhance telemetry payloads with additional fields and serialization support

Added new fields to the ComponentPayload and ComponentInputsPayload classes, including component_id and component_run_id, to improve telemetry data tracking. Introduced a serialize_input_values function to handle JSON serialization of component input values, ensuring robust handling of input data for telemetry purposes.

* feat: Implement telemetry input tracking and caching

Added functionality to track and cache telemetry input values within the Component class. Introduced a method to determine if inputs should be tracked based on sensitivity and an accessor for retrieving cached telemetry data, enhancing the robustness of telemetry handling.

* feat: Add logging for component input telemetry

Introduced a new method, log_package_component_inputs, to the TelemetryService for logging telemetry data related to component inputs. This enhancement improves the tracking capabilities of the telemetry system, allowing for more detailed insights into component interactions.

* feat: Enhance telemetry logging for component execution

Added functionality to log component input telemetry both during successful execution and error cases. Introduced a unique component_run_id for each execution to improve tracking. This update ensures comprehensive telemetry data collection, enhancing the robustness of the telemetry system.

* feat: Extend telemetry payload tests and enhance serialization

Added tests for the new component_id and component_run_id fields in ComponentPayload and ComponentInputsPayload classes. Introduced a new test suite for ComponentInputTelemetry, covering serialization of various data types and handling of edge cases. This update improves the robustness and coverage of telemetry data handling in the system.

* fix: Update default telemetry tracking behavior in BaseInputMixin

Changed the default value of track_in_telemetry from True to False in the BaseInputMixin class. Updated documentation to clarify that telemetry tracking is now opt-in and can be explicitly enabled for individual input types, enhancing data privacy and control.

* fix: Update telemetry tracking defaults for input types

Modified the default value of `track_in_telemetry` for various input classes to enhance data privacy. Regular inputs now default to False, while safe inputs like `IntInput` and `BoolInput` default to True, ensuring explicit opt-in for telemetry tracking. Updated related tests to reflect these changes.

* feat: add chunk_index and total_chunks fields to ComponentInputsPayload

This commit adds two new optional fields to ComponentInputsPayload:
- chunk_index: Index of this chunk in a split payload sequence
- total_chunks: Total number of chunks in the split sequence

Both fields default to None and use camelCase aliases for serialization.
This is Task 1 of the telemetry query parameter splitting implementation.

Tests included:
- Verify fields exist and can be set
- Verify camelCase serialization aliases work correctly
- Verify fields default to None when not provided

Generated with Claude Code (https://claude.com/claude-code)



* refactor: update ComponentInputsPayload to support automatic splitting of oversized inputs

This commit enhances the ComponentInputsPayload class by implementing functionality to automatically split input values into multiple chunks if they exceed the maximum URL size limit. Key changes include:

- Added methods for calculating URL size, truncating oversized values, and splitting payloads.
- Updated component_inputs field to accept a dictionary instead of a string for better handling of input values.
- Improved documentation for the ComponentInputsPayload class to reflect the new splitting behavior and usage examples.

These changes aim to improve telemetry data handling and ensure compliance with URL length restrictions.

* refactor: enhance log_package_component_inputs to handle oversized payloads

This commit updates the log_package_component_inputs method in the TelemetryService class to split component input payloads into multiple requests if they exceed the maximum URL size limit. Key changes include:

- Added logic to split the payload using the new split_if_needed method.
- Each chunk is queued separately for telemetry logging.

These improvements ensure better handling of telemetry data while adhering to URL length restrictions.

* refactor: centralize maximum telemetry URL size constant

This commit introduces a centralized constant, MAX_TELEMETRY_URL_SIZE, to define the maximum URL length for telemetry GET requests. Key changes include:

- Added MAX_TELEMETRY_URL_SIZE constant to schema.py for better maintainability.
- Updated split_if_needed method in ComponentInputsPayload to use the new constant instead of a hardcoded value.
- Adjusted the TelemetryService to reference the centralized constant for URL size limits.

These changes enhance code clarity and ensure consistent handling of URL size limits across the telemetry service.

* refactor: update ComponentInputsPayload tests to use dictionary inputs

This commit modifies the tests for ComponentInputsPayload to utilize a dictionary for component inputs instead of a serialized JSON string. Key changes include:

- Renamed the test method to reflect the new input type.
- Removed unnecessary serialization steps and assertions related to JSON strings.
- Added assertions to verify the correct handling of dictionary inputs.

These changes streamline the testing process and improve clarity in how component inputs are represented.

* test: add integration tests for telemetry service payload splitting

This commit introduces integration tests for the TelemetryService to verify its handling of large and small payloads. Key changes include:

- Added tests to ensure large payloads are split into multiple chunks and queued correctly.
- Implemented a test to confirm that small payloads are not split and result in a single queued event.
- Created a mock settings service for testing purposes.

These tests enhance the reliability of the telemetry service by ensuring proper payload management.

* test: enhance ComponentInputsPayload tests with additional scenarios

This commit expands the test suite for ComponentInputsPayload by adding various scenarios to ensure robust handling of input payloads. Key changes include:

- Introduced tests for calculating URL size, ensuring it returns a positive integer and accounts for encoding.
- Added tests to verify the splitting logic for large payloads, including checks for chunk metadata and preservation of fixed fields.
- Implemented property-based tests using Hypothesis to validate that all chunks respect the maximum URL size and preserve original data.

These enhancements improve the reliability and coverage of the ComponentInputsPayload tests, ensuring proper functionality under various conditions.

* [autofix.ci] apply automated fixes

* optimize query param encoding



* refactor: extract telemetry logging logic into a separate function

This commit introduces a new function, _log_component_input_telemetry, to centralize the logic for logging component input telemetry. The function is called in two places within the generate_flow_events function, improving code readability and maintainability by reducing duplication. This change enhances the clarity of telemetry handling in the flow generation process.

* refactor: optimize truncation logic in ComponentInputsPayload

This commit refines the truncation logic for input values in the ComponentInputsPayload class. The previous binary search method for string values has been simplified, allowing for direct truncation of both string and non-string values. This change enhances code clarity and maintains functionality while ensuring optimal handling of oversized inputs.

* refactor: update telemetry tracking logic to respect opt-in flag

This commit modifies the telemetry tracking logic in the Component class to change the default behavior of the `track_in_telemetry` attribute from True to False. This adjustment enhances user privacy by requiring explicit consent for tracking input objects in telemetry. The change ensures that sensitive field types are still auto-excluded from tracking, maintaining the integrity of the telemetry data.

* refactor: update tests to use dictionary format for component inputs

This commit modifies the integration tests for telemetry payload validation and component input telemetry to utilize dictionaries for component inputs instead of serialized JSON strings. Key changes include:

- Updated assertions to compare dictionary inputs directly.
- Enhanced clarity and maintainability of the test cases by removing unnecessary serialization steps.

These changes improve the representation of component inputs in tests, aligning with recent refactoring efforts.

* [autofix.ci] apply automated fixes

* refactor: specify type for current_chunk_inputs in ComponentInputsPayload

This commit updates the type annotation for the current_chunk_inputs variable in the ComponentInputsPayload class to explicitly define it as a dictionary. This change enhances code clarity and maintainability by providing better type information for developers working with the code.

* test: add component_id to ComponentPayload tests

This commit enhances the test cases for the ComponentPayload class by adding a component_id parameter to various initialization tests. The updates ensure that the component_id is properly tested across different scenarios, including valid parameters, error messages, and edge cases. This change improves the robustness of the tests and aligns with recent updates to the ComponentPayload structure.

* [autofix.ci] apply automated fixes

* feat: add component_id to ComponentPayload in build_vertex function

* fix: update MAX_TELEMETRY_URL_SIZE to 2048 and adjust related tests

This commit increases the maximum URL size for telemetry GET requests from 2000 to 2048 bytes to align with Scarf's specifications. Corresponding test assertions have been updated to reference the new constant, ensuring consistency across the codebase.

* [autofix.ci] apply automated fixes

* feat(telemetry): add track_in_telemetry field to starter project configurations

* refactor(telemetry): remove unused blank line in test imports

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* update starter templates

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

---------





* fix(telemetry): resolve cyclic import in telemetry service (#10598)

* fix(telemetry): resolve cyclic import by moving get_email_model

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

---------



* feat: Add gpt-5.1 model to Language models (#10590)

* Add gpt-5.1 model to starter projects

Added 'gpt-5.1' to the list of available models in all starter project JSON files to support the new model version. This update ensures users can select gpt-5.1 in agent configurations.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Update component_index.json

* [autofix.ci] apply automated fixes

* Update component_index.json

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------



* fix: Use the proper Embeddings import for Qdrant vector store (#10613)

* Use the proper Embeddings import for Qdrant vector store

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------




* fix: Ensure split text test is more robust (#10622)

* fix: Ensure split text test is more robust

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------



* docs: security notice (#10555)

* docs-security-notice

* Apply suggestions from code review



* code-review

* link-to-security-bulletin

* Apply suggestions from code review



---------



* fix: use issubclass in the pool creation (#10232)

* use issubclass in the pool creation

* [autofix.ci] apply automated fixes

* add poolclass pytests

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------





* docs: OpenAPI spec version upgraded from 1.6.5 to 1.6.8 (#10627)




* chore: Fix indentation on bundles-docling.mdx (#10640)

* feat: make it possible to load graphs using `get_graph` function in scripts (#9913)

* feat: Enhance graph loading functionality to support async retrieval

- Updated `load_graph_from_script` to be an async function, allowing for the retrieval of the graph via an async `get_graph` function if available.
- Implemented fallback to the existing `graph` variable for backward compatibility.
- Enhanced `find_graph_variable` to identify both `get_graph` function definitions and `graph` variable assignments, improving flexibility in script handling.

* feat: Update load_graph_from_script to support async graph retrieval

- Refactored `load_graph_from_script` to be an async function, enabling the use of an async `get_graph` function for graph retrieval.
- Implemented a fallback mechanism to access the `graph` variable for backward compatibility.
- Enhanced error handling to provide clearer messages when neither `graph` nor `get_graph()` is found in the script.

* feat: Refactor simple_agent.py to support async graph creation

- Introduced an async `get_graph` function to handle the initialization of components and graph creation without blocking.
- Updated the logging configuration and component setup to be part of the async function, improving the overall flow and responsiveness.
- Enhanced documentation for the `get_graph` function to clarify its purpose and return type.

* feat: Update serve_command and run functions to support async graph loading

- Refactored `serve_command` to be an async function using `syncify`, allowing for non-blocking execution.
- Updated calls to `load_graph_from_path` and `load_graph_from_script` within `serve_command` and `run` to await their results, enhancing performance and responsiveness.
- Improved overall async handling in the CLI commands for better integration with async workflows.

* feat: Refactor load_graph_from_path to support async execution

- Changed `load_graph_from_path` to an async function, enabling non-blocking graph loading.
- Updated the call to `load_graph_from_script` to use await, improving performance during graph retrieval.
- Enhanced the overall async handling in the CLI for better integration with async workflows.

* feat: Enhance async handling in simple_agent and related tests

- Updated `get_graph` function in `simple_agent.py` to utilize async component initialization for improved responsiveness.
- Modified test cases in `test_simple_agent_in_lfx_run.py` to validate the async behavior of `get_graph`.
- Refactored various test functions across multiple files to support async execution, ensuring compatibility with the new async workflows.
- Improved documentation for async functions to clarify their purpose and usage.

* docs: Implement async get_graph function for improved component initialization

- Introduced an async `get_graph` function in `README.md` to facilitate non-blocking component initialization.
- Enhanced the logging configuration and component setup within the async function, ensuring a smoother flow.
- Updated documentation to clarify the purpose and return type of the `get_graph` function, aligning with the async handling improvements.

* refactor: reorder imports in simple_agent test file

* style: reorder imports in simple_agent test file

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* update component index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------



* feat: Add custom download node function (#10659)

* add custom download node

* use download node

* feat: Add type check before issubclass in service discovery (#10636)

* Add type check before issubclass in service discovery

Added an isinstance(obj, type) check before issubclass to prevent errors when inspecting module members for Service and ServiceFactory subclasses. This improves robustness when dynamically importing services and factories.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

---------



* docs: readme update  (#10657)

* dep-management

* are

* fix: minor redesign of guardrails for disabling components in LF Astra cloud (#10662)

* create cloud validation util file

disable local_db if in astra cloud

disable split_video if in astra cloud

disable video_file component if in astra cloud

ruff (video_file.py)

correct the error message in video_file.py

disable mem0 and composio in astra cloud

update astra disable component util fn name to be more descriptive

add tests for disabling components

minor docs patch

remove component disable check in places that interact with building the component index

replace init test with execution in composio unit test suite

remove dotenv from validate_cloud

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------



* fix: prevent autofix workflow loop from bot commits (#10673)

fix(ci): prevent autofix workflow loop from bot commits

* fix(lfx-dev): reload specific modules while preserving index cache (#10629)

* fix(lfx-dev): reload specific modules while preserving index cache

* refactor: restructure component loading with strategy pattern for dev mode

* fix: improve cache loading error handling in component index loading

* refactor: reorganize CUGA and ALTK components into single-element bundles (#10671)

* moved cuga and altk

* reverted starter templates

* [autofix.ci] apply automated fixes

* updated import

* [autofix.ci] apply automated fixes

* revert starter templates

* fixed some python tests

* fix: update import assertions for backward compatibility in dynamic import tests

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* fix: update import paths for set_advanced_true and get_parent_agent_inputs in test_helper_functions

---------



* feat: fix cuga component with new release (#10646)

* bufix(cuga_agent): fixed no output chat bug

* fix: remove structured output feature

* fix: stablize component

* fix: chat output component not working

* fix: add strategy flag

* fix: update cuga version

* feat: add component index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* update some imports to use lfx

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* fix: update review

* chore: build component index

* chore: build component

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* fix(cuga): ensure message id exists when not connected to output

* fix: component result id on chat output

* chore: fix component index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Revert test_agent_component.py back to origin/main

* fix: remove unwanted tests

* chore: new build index

* [autofix.ci] apply automated fixes

* fix: update test

* chore: build index

* [autofix.ci] apply automated fixes

* fix: update package of cuga

* chore: build component index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* update comp index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* trying comp index again?

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

---------





* fix: Add IBM watsonx.ai support to EmbeddingModel (#10677)

* Add IBM watsonx.ai support to EmbeddingModel

Added IBM watsonx.ai as a supported provider in EmbeddingModelComponent, updated dependencies and code to integrate ibm_watsonx_ai and pydantic. Updated starter project and component index metadata to reflect new dependencies and code changes.

* update watsonx default models

* update index

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Update test_embedding_model_component.py

* Update component_index.json

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------



* fix: rename LLM router to LLM selector (#10650)

* fix: rename LLM router to LLM selector

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* fix: rename LLMRouter component to LLMSelector

* fix: resolved merge conflicts

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* fix: resolved merge conflicts

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* fix: refactor file name

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* fix: resolve merge conflict

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* fix: resolve merge conflict

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

---------



* Fix: add environment variable flag to log alembic to stdout (#10620)

* fix: add flag to log alembic to stdout

fix indentation

refine docs

mypy (db service.py)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------



* fix: move sql database to data source category (#10651)

* fix: move sql database to data source category

* [autofix.ci] apply automated fixes

* fix: resolve merge conflict

---------



* fix: fixes YouTube Icon name in lazyloadingMapping (#10628)

* fix lazyloadingMapping component name

* fix: merge conflicts

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes

* fix: resolve merge conflict

---------



* Fix: rename sidebar category flow controls to flow control (#10649)

* rename sidebar category flow controls to flow control

* fix: addressed PR comments

* fix: expose logger functions at module level for backwards comp (#10670)

* Expose logger functions at module level for backwards comp

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

---------



* feat: agentic UX (#10567)

* Add empty __init__.py files for agentic modules

Created empty __init__.py files in agentic, core, tools, and utils directories to initialize them as Python packages.

* Add agentic template search utilities and tests

Introduces a new agentic utilities module for Langflow, including template search, tag extraction, and template count functions. Adds a README, demo script, and comprehensive unit tests for template search functionality.

* Add Langflow Agentic MCP server with FastMCP tools

Introduces a new MCP (Model Context Protocol) server for Langflow agentic tools using FastMCP. Adds server, CLI, example usage, tests, and comprehensive documentation. Exposes four MCP tools: search_templates, get_template, list_all_tags, and count_templates, enabling AI assistants to query and filter Langflow templates programmatically.

* Handle unparameterized list types in schema inputs

Adds support for unparameterized list annotations by treating them as lists of strings when converting schemas to Langflow inputs. This ensures nullable array schemas without explicit item types are handled gracefully.

* Refactor search_templates to simplify parameters

Removed the 'tags' parameter from the search_templates function and set a default value for 'fields'. Updated the call to list_templates to match the new signature, streamlining template search functionality.

* Add output item processing for tool results

Introduced process_output_item to handle tool output items, attempting to parse text-type items as JSON. This improves downstream handling of tool outputs by converting JSON strings to dictionaries when possible.

* Refactor knowledge base path initialization

Replaces direct settings access with a lazy-loading function for the knowledge bases root path in Knowledge Ingestion and Knowledge Retrieval starter projects. This improves reliability and consistency when accessing the knowledge base directory, and updates all usages to the new helper function.

* Update component_index.json

* Add IBM watsonx.ai support to starter projects

Introduces IBM watsonx.ai as a selectable model provider in multiple starter project JSONs. Adds new input fields for 'base_url', 'project_id', and 'max_output_tokens' to support IBM watsonx.ai integration. Updates agent component code to handle new provider and its required parameters.

* Add Ollama to supported LLM providers in starter projects

Ollama has been added as a supported provider alongside Anthropic, Google Generative AI, OpenAI, and IBM watsonx.ai in all starter project JSON files. This expands the available options for LLM integration in initial setup templates.

* Update Ollama model input constants and logic

Refactored model_input_constants.py to update the OLLAMA_MODEL_INPUTS and OLLAMA_MODEL_INPUTS_MAP. Modified ollama.py to use the new input mapping and improved input handling for Ollama components.

* Add flow creation from template MCP tool

Introduces a new MCP tool for creating flows from starter templates in Langflow Agentic. Adds the utility function `create_flow_from_template_and_get_link` and exposes it via the FastMCP server, allowing users to create flows by template id and receive a UI link. Updates imports and documentation accordingly.

* Add component search utilities and MCP tools to server

Introduces new component search and retrieval tools to the MCP server, including endpoints for searching, listing, and counting components. Adds support functions in support.py for data normalization and a new component_search.py utility module. Updates the Nvidia Remix starter project to use the latest MCPToolsComponent code.

* Add flow graph visualization utilities

Introduces async utility functions for generating ASCII and text representations of flow graphs, as well as metadata summaries. These utilities support fetching flows by ID or name, error handling, and integration with Langflow's graph and logging modules.

* Add flow component operations utilities and MCP tools

Introduces flow component management utilities in `flow_component.py` for retrieving, updating, and listing component field values. Exposes new MCP tools in `server.py` for accessing component details, field values, updating fields, and listing all fields within a flow component.

* Add SystemMessageGen flow and update MCPTools

Introduces SystemMessageGen.json flow for agentic system message generation and updates MCPTools component logic in flow_component.py to support new flow structure and tool handling.

* feat: init aiButton

create an aiButton that opens the prompt modal for demoing
add multiinput mixin

* Update component_index.json

* Refactor SystemMessageGen flow and remove unused init files

Updated SystemMessageGen.json to support custom instructions, OpenAI model configuration, and improved agent settings. Removed unused __init__.py files from agentic, core, tools, and utils directories to clean up the codebase.

* update to the mcp component

* Add verify_ssl option to MCPToolsComponent

Introduces a 'verify_ssl' boolean input to MCPToolsComponent for controlling SSL certificate verification in HTTPS connections. The option is added to the server config if not present, allowing users to disable verification for development or testing with self-signed certificates.

* Optimize tool dropdown handling and output processing

Improves logic for updating tool dropdown options by checking if the server has changed and whether tool mode is active, reducing unnecessary updates. Adds a process_output_item method to parse tool output as JSON when appropriate, enhancing output handling.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* feat: init onclick assistant prompt generation

first pass at on button click generate input and auto fill a field

* Replace MCPTools with Prompt Template in SystemMessageGen flow

Updated the SystemMessageGen.json flow to use the Prompt Template and Parser components instead of MCPTools. Adjusted edges, nodes, and component configurations to reflect the new prompt-based workflow, removing tool selection and execution logic in favor of prompt generation and parsing.

* Update SystemMessageGen flow and frontend dependencies

Refactored edge connections and metadata in SystemMessageGen.json to improve flow logic and updated endpoint name. Added new optional and peer dependencies to package-lock.json, including @mapbox/node-pre-gyp and related packages, to support canvas and other modules.

* Update user authentication in simplified_run_flow endpoint

Replaces the dependency on api_key_security with CurrentActiveUser for the api_key_user parameter in the simplified_run_flow endpoint. This change is part of a TODO to create a new endpoint and may affect how user authentication is handled.

* feat: hook everything up and have onclick prompt

hook up commit

* Add auto-configuration for Agentic MCP server

Introduces utilities and startup logic to automatically configure the Langflow Agentic MCP server for all users when the agentic experience is enabled. Adds a new settings flag `agentic_experience` to control this feature, and updates the main server startup to trigger configuration. This enables agentic tools for flow/component operations, template search, and graph visualization in MCP clients.

* Enable agentic MCP server and improve initialization

Set agentic_experience to True by default in settings. Refactor agentic MCP server initialization in main.py to run in the background with a delay and retry logic, improving startup reliability. Update function calls to use 'current_user' instead of 'user' in agentic_mcp.py for consistency.

* Update user authentication in simplified_run_flow

Modified the api_key_user parameter to accept either CurrentActiveUser or UserRead from api_key_security, supporting both Bearer and session authentication methods.

* revert the apikeu_user changes

* test new api endpoint

* Refactor agent flow and update component inputs

Updated SystemMessageGen.json to refactor edge connections and node IDs for agentic flow. Added 'base_url' as a required input, enabled 'ai_enabled' for agent description, and replaced static memory input handling with dynamic retrieval via get_base_inputs(). Also improved tool callback setup and updated code hash and last_updated metadata.

* Improve agentic flow creation and updating logic

Enhances the agentic flow setup to extract flow_id and endpoint_name from JSON, update existing flows by ID or endpoint_name, and create new flows if they don't exist. Adds detailed logging and ensures flows are up-to-date in the user's Langflow Assistant folder.

* chore: aibutton clean up

* chore: add assistant store

* Update SystemMessageGen.json

* Update agentic_mcp.py

* Update component_index.json

* Fix agent input extraction from Message objects

Agents now correctly extract and use the text content from Message objects, rather than passing the entire object or its string representation. This resolves issues where agents received verbose message representations instead of just the intended string input, and includes improved handling for multimodal content. Corresponding unit and integration tests have been added to verify this behavior for both OpenAI and Anthropic agents.

* Add TemplateAssistant Langflow flow definition

Introduces TemplateAssistant.json, a comprehensive Langflow flow configuration for agentic workflows. This flow integrates AstraDB, MCP Tools, and user input/output nodes, enabling document ingestion, search, and tool orchestration within the Langflow backend.

* Improve MCPToolsComponent server/tool config refresh

Refactored MCPToolsComponent to better handle tool and server config refreshes, especially when the MCP server changes. Added logic to avoid unnecessary clearing of tool inputs and options, and improved caching and UI update behavior for tool selection. Also updated related flow and starter project JSON files to reflect these changes.

* auto add Global Variables for Agentic Experience

* chore: clean up and get button working again

* cleanup .md

* fix:ruff, Refactor agentic utils and improve error handling

Introduces shared default field lists for template/component search, refactors exception handling to use logger and add finally/else blocks, and improves type hinting with TYPE_CHECKING. Updates file opening to use Path objects, enhances error logging in template search, and removes the unused test_template_search.py file.

* fix:ruff Expand exception handling in agentic MCP utilities

Broadened exception handling in agentic MCP server and variable management functions to catch specific errors such as HTTPException, SQLAlchemyError, and common system exceptions. This improves robustness and error logging during server configuration, removal, and variable initialization.

* aka-clean-up-1

* Remove duplicate process_output_item method

Deleted two redundant definitions of the process_output_item method from MCPToolsComponent to clean up the code and prevent confusion.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes

* Refactor service usage and improve project deletion logging

Refactored login API to reuse a single settings service instance. Enhanced logging and error messaging when attempting to delete the Langflow Assistant folder. Minor variable usage cleanup in agentic flows setup and agent component test.

* [autofix.ci] apply automated fixes (attempt 2/3)

* Update test_template_search.py

* Handle specific exceptions in agentic flow loading

Updated the exception handling in load_agentic_flows to catch only OSError and orjson.JSONDecodeError instead of all exceptions, improving error specificity and logging.

* Update component_index.json

* [autofix.ci] apply automated fixes

* revert loading setting service

* Update login.py

* Update SystemMessageGen.json

* Update TemplateAssistant.json

* [autofix.ci] apply automated fixes

* Update constants.py

* chore: seperate templateassistant and sysmessgen

seperate templateassistant and sysmessgen frontend queries

* chore: add header feature flag

* use feature flag for all ui

* [autofix.ci] apply automated fixes

* package-lcok update

* [autofix.ci] apply automated fixes

* chore: LANGFLOW_AGENTIC_EXPERIENCE fe ff name

* Update login.py

* lint fix

* [autofix.ci] apply automated fixes

* Update component_index.json

* chore: fix adjust-screan-view click

* chore: same force issue as adjust-screen-view

* chore: playwright pass 2

* revert package-lock

* add type to langflow_modules

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* Handle TypeError in class-based serialization

Adds a try-except block to catch TypeError when checking issubclass for objects that are types but not proper classes, such as typing special forms. This prevents serialization errors for generic aliases and similar constructs.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* Refactor type handling in field update and serialization

Changed 'new_value' parameter type to str in update_flow_component_field for stricter typing. Simplified exception handling in serialize by removing unnecessary try/except around issubclass checks for class-based Pydantic types.

---------




* ci: bump actions/checkout to v6 (#10697)

* feat: Improve OAuth error handling and frontend sync behavior (#10626)

* updates for version comp

* migrate mcp composer fix to main

* migrate mcp composer fix to main

* version constraints

* go back to pydantic 2.11

* remove logging

* directly pin to new version

* add instant feedback on error

* improve callback function behavior ux

* fix tests and mypy issues

* bump mcp composer version

* fixed latest version mcp

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* revert pydantic changes

* computed models pydantic fix

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------





* fix: Fix TypeError when LANGFLOW_ENABLE_LOG_RETRIEVAL is enabled (#10681)

* fix serialize issue when LANGFLOW_ENABLE_LOG_RETRIEVAL is true

* add logger tests

* [autofix.ci] apply automated fixes

* add multiple buffer checker

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* use serialize instead

* [autofix.ci] apply automated fixes

---------




* docs: update component documentation links to individual pages

* Revert "docs: update component documentation links to individual pages"

This reverts commit 1da51d4ccba9458506da6ff5b1ab7af23f09c2b6.

* test: catch import errors upfront (#10632)

* Convert to async and ruff-friendly print

* Implement the checking into existing test file itself

* Remove the newly introduced lfx test which is now incorporated into existing tests

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Run make build_component_index after merging latest from main

* [autofix.ci] apply automated fixes

* Revert "docs: update component documentation links to individual pages"

This reverts commit 1da51d4ccba9458506da6ff5b1ab7af23f09c2b6.

* build component index after origin/main merge into feature branch

* [autofix.ci] apply automated fixes

---------





* feat: Support appending files when saving (#10631)

* feat: Support appending files when saving

* Update save_file.py

* Update News Aggregator.json

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Update save_file.py

* Update save_file.py

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes

* Overwrite existing file if append mode is true

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Update test_mcp_servers_file.py

* [autofix.ci] apply automated fixes

* Update save_file.py

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------



* chore: Update pip and setuptools version constraints (#10708)

* update setuptools and pip

* remove from lfx pypoetry

* feat: Display node name in download error message (#10707)

add component name on download error

* feat: Add Message Support for Input of Loop Component (#10160)

* feat: Add support for messages in Loop Component

* feat: Add Message support for input of Loop Component

* [autofix.ci] apply automated fixes

* Update src/frontend/src/utils/reactflowUtils.ts



* [autofix.ci] apply automated fixes

* More cleanup of looping

* Fix ruff errors

* [autofix.ci] apply automated fixes

* Update loop-component.spec.ts

* Make loop types generic

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Fixes from gabriel review

* [autofix.ci] apply automated fixes

---------





* fix: Support tool mode in File Component properly (#10520)

* Support tool mode in dynamic outputs

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Tool mode and ruff fixes

* Template updates

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* Update test_mcp_servers_file.py

* Revert "Update test_mcp_servers_file.py"

This reverts commit 25f24d0d8aa5a7c95c913f862d86513749195ad1.

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* add possibility for the agent to access the processed output file

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

---------





* docs: include regex for sanitized input types (#10712)

include-regex-for-sanitized-input

* feat: Version 1.2 - comprehensive database migration guidelines using… (#10519)

* feat: Version 1.2 - comprehensive database migration guidelines using the Expand-Contract pattern

* Update src/backend/base/langflow/alembic/DB-MIGRATION-GUIDE.MD



* fix: Cleanup text and typos

* feat: Implement migration validation workflow and add migration validator scripts

* Update src/backend/base/langflow/alembic/migration_validator.py



* Update src/backend/base/langflow/alembic/migration_validator.py



* Update src/backend/base/langflow/alembic/migration_validator.py



* fix: moved the test_migrations directory to under tests

* feat: Added migration validator to pre-commit check.

* fix: improved test performance.

* fix: optimized attribute resolution in migration validator

* feat: add comprehensive tests for migration validator and guidelines

* fix: Lint is complaining about shebang declared but not being used.

* fix: Shebang reinstated.

* Update src/backend/base/langflow/alembic/DB-MIGRATION-GUIDE.MD

Co-authored-by: Copilot <175728472+Copilot@users.…

Co-authored-by: Rodrigo Nader <rodrigosilvanader@gmail.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Mendon Kissling <59585235+mendonk@users.noreply.github.com>
Co-authored-by: Gabriel Luiz Freitas Almeida <gabriel@langflow.org>
Co-authored-by: Jordan Frazier <122494242+jordanrfrazier@users.noreply.github.com>
Co-authored-by: Mike Fortman <michael.fortman@datastax.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Edwin Jose <edwin.jose@datastax.com>
Co-authored-by: Jordan Frazier <jordan.frazier@datastax.com>
Co-authored-by: Deon Sanchez <69873175+deon-sanchez@users.noreply.github.com>
Co-authored-by: Tejas Kumar <tejas.kumar@datastax.com>
Co-authored-by: cristhianzl <cristhian.lousa@gmail.com>
Co-authored-by: Adam Aghili <Adam.Aghili@ibm.com>
Co-authored-by: Uday Sidagana <129588963+Uday-sidagana@users.noreply.github.com>
Co-authored-by: Koren Lazar <44236526+korenLazar@users.noreply.github.com>
Co-authored-by: Koren Lazar <koren.lazar@ibm.com>
Co-authored-by: Sami Marreed <sami.marreed@ibm.com>
Co-authored-by: codeflash-ai[bot] <148906541+codeflash-ai[bot]@users.noreply.github.com>
Co-authored-by: Madhavan <msmygit@users.noreply.github.com>
Co-authored-by: Madhavan <cxo@ibm.com>
Co-authored-by: Eric Hare <ericrhare@gmail.com>
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
Co-authored-by: ming <itestmycode@gmail.com>
Co-authored-by: Hamza Rashid <74062092+HzaRashid@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-merge-queue <118344674+github-merge-queue@users.noreply.github.com>
Co-authored-by: Himavarsha <40851462+HimavarshaVS@users.noreply.github.com>
Co-authored-by: Offer Akrabi <offer.akrabi@il.ibm.com>
Co-authored-by: keval shah <kevalvirat@gmail.com>
Co-authored-by: Rej Ect <99460023+rejected-l@users.noreply.github.com>
Co-authored-by: Hamza Rashid <hzarashid@gmail.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: Carlos Coelho <80289056+carlosrcoelho@users.noreply.github.com>
Co-authored-by: Rico Furtado <hfurtado@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Cristhian Zanforlin <criszl@192.168.15.88>
Co-authored-by: Wallgau <46035189+Wallgau@users.noreply.github.com>
Co-authored-by: Olfa Maslah <olfamaslah@Olfas-MacBook-Pro.local>
Co-authored-by: Cristhian Zanforlin <criszl@MacBook-Pro-di-Cristhian.local>
Co-authored-by: Olfa Maslah <olfamaslah@macbookpro.war.can.ibm.com>
Co-authored-by: kiran-kate <40038037+kiran-kate@users.noreply.github.com>
Co-authored-by: olayinkaadelakun <olayinka.adelakun@ibm.com>
Co-authored-by: Olayinka Adelakun <olayinkaadelakun@Olayinkas-MacBook-Pro.local>
Co-authored-by: Olayinka Adelakun <olayinkaadelakun@mac.war.can.ibm.com>
Co-authored-by: Joao Paulo Ramos <joao.oramos11@gmail.com>
Co-authored-by: phact <estevezsebastian@gmail.com>
Co-authored-by: Steve Haertel <stevehaertel@users.noreply.github.com>
Co-authored-by: Steve Haertel <shaertel@ca.ibm.com>
Co-authored-by: Simon Steinbeiß <simon.steinbeiss@elfenbeinturm.at>
Co-authored-by: Mike Pawlowski <mpawlow@ca.ibm.com>
Co-authored-by: Viktor Avelino <64113566+viktoravelino@users.noreply.github.com>
Co-authored-by: himavarshagoutham <himavarshajan17@gmail.com>
Co-authored-by: Jason Tsay <jsntsay@gmail.com>
Co-authored-by: andifilhohub <115162146+andifilhohub@users.noreply.github.com>
Co-authored-by: Ali Saleh <saleh.a@turing.com>
Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: phact <1313220+phact@users.noreply.github.com>
Co-authored-by: avonian <ara@soundstage.fm>
Co-authored-by: Ara Kevonian <avonian@users.noreply.github.com>
Co-authored-by: Adam-Aghili <149833988+Adam-Aghili@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Lucas Democh <ldgoularte@gmail.com>
Co-authored-by: Jason Tsay <jason.tsay@ibm.com>
Co-authored-by: Lucas Oliveira <62335616+lucaseduoli@users.noreply.github.com>
Co-authored-by: Janardan Singh Kavia <janardankavia@ibm.com>
Co-authored-by: Janardan S Kavia <janardanskavia@mac.myfiosgateway.com>
Co-authored-by: Lucas Oliveira <lucas.edu.oli@hotmail.com>
Co-authored-by: Rodrigo Nader <rodrigonader@MacBook-Pro-de-Rodrigo.local>
Co-authored-by: Janardan S Kavia <janardanskavia@Janardans-MacBook-Pro.local>
Co-authored-by: Janardan S Kavia <janardanskavia@mac.war.can.ibm.com>
Co-authored-by: Antônio Alexandre Borges Lima <104531655+AntonioABLima@users.noreply.github.com>
Co-authored-by: Antônio Alexandre Borges Lima <antonio@Antonios-MacBook-Pro.local>
Co-authored-by: Debojit Kaushik <Kaushik.debojit@gmail.com>
Co-authored-by: Debojit Kaushik <debojitkaushik@Debojits-MacBook-Pro.local>
Co-authored-by: necrophcodr <necrophcodr@users.noreply.github.com>
Co-authored-by: Phil Nash <philnash@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working fix Bug fixes and patches lgtm This PR has been approved by a maintainer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants