How to use this reference
The merged fix resolves applications under the authenticated tenant before tracing operations and returns the same denial as an absent application. It covers configuration and tracing handlers and later adds cross-tenant regression coverage. Editorial lesson: treat observability configuration as data-export authority, with authorization independent of ordinary application-client access.
Before reading
- Tenant-scoped object authorization
- AI telemetry flows and external data recipients
Context and limits
- The detailed research requires a console account and an application identifier. Its introductory unauthenticated framing must not replace these stated prerequisites. Application-client access is not administration permission.
- The researcher’s article covers four findings; this resource covers only tracing authorization. No production victim, exposure count or individual award is established.
- The fix merged May 14, 2026. Official v1.14.2 notes include it; the researcher dates that software release May 19, 2026 and discusses v1.15.0 as the broader four-finding remediation. These are not educational-edition dates.
- The research timeline also places an April 2025 last-report publication before its December 2025 first report, and lists a June 25 release after its displayed June 22 publication. Those inconsistent dates are not silently repaired.
- No regression tests were executed in this review. Public disclosure grants no testing authorization.
Sources and provenance
- DifyTap research Zafran Labs · reviewed 2026-10-03
- Tenant-scoping fix for tracing configuration Dify · reviewed 2026-10-03
- Dify v1.14.2 release notes Dify · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.