← Back to Full-Featured Custom Word .docx Generator · JSON Edition
Privacy Policy / 隐私政策
Data handled
The plugin reads the JSON, files and image references supplied to a Tool invocation and generates the DOCX inside the Dify plugin runtime. It does not send the document to a third-party document-generation service and does not intentionally persist the input or output after the invocation.
When an image is supplied as a Dify File/Blob, raw bytes, Base64 or a data: URL, it is processed locally. When an image is supplied as an HTTP(S) URL—or when a relative /files/... reference must be completed—the plugin sends a GET request to the resolved Dify or remote image host. The destination receives normal request metadata and the complete path/query, including any signed query parameters. Users must only provide URLs they are authorised to access.
Self-hosted Dify file URLs may legitimately resolve to private, loopback, container-DNS or reverse-proxy addresses, so those destinations are supported. Cloud-instance metadata addresses and non-HTTP(S) schemes are rejected. Redirects are checked and limited to three. Fetching is time-bounded, each response is capped at 50 MiB before image decoding, and a document is capped at 200 MiB of unique fetched image bytes. Only decodable image content is inserted. A failed or unsafe fetch becomes an in-document notice and does not stop the remaining document.
The plugin does not intentionally log URL query strings or user document content. Dify administrators remain responsible for runtime logs, network egress policy and storage configured around the plugin.
处理的数据
插件读取当次 Tool 调用提供的 JSON、文件和图片引用,在 Dify 插件运行时内生成 DOCX;不会把文档交给第三方文档生成服务,也不会在调用结束后主动持久保存输入或输出。
图片以 Dify File/Blob、原始字节、Base64 或 data: URL 提供时,仅在本地处理。图片以 HTTP(S) URL 提供,或根相对 /files/... 需要补全来源时,插件会向解析出的 Dify/远端图片主机发起 GET;目标主机会收到常规请求信息及完整路径/查询串(包括签名参数)。用户应只提交自己有权访问的地址。
自托管 Dify 的文件地址可能位于私网、回环、容器 DNS 或反向代理后,因此这些目标被允许;云实例元数据地址和非 HTTP(S) 协议会被拒绝。重定向逐跳检查且最多三次;取图有总时限,单个响应在解码前最多 50 MiB,每份文档的去重下载图片累计最多 200 MiB;只有可解码图片会写入文档。不安全或失败的图片只转为文档内提示,不中断其余内容。
插件不会主动记录 URL 查询串或用户正文。插件外围的运行日志、网络出口和存储策略由 Dify 管理员负责。