Commit Graph
210 Commits
Author SHA1 Message Date
google-labs-jules[bot]andAEmotionStudio bb8166cc8f Address PR feedback (no code changes)
Co-authored-by: AEmotionStudio <163354043+AEmotionStudio@users.noreply.github.com>
2026-02-09 23:28:34 +00:00
google-labs-jules[bot]andAEmotionStudio 6de50104f1 Fix path traversal vulnerability in file output validation
Co-authored-by: AEmotionStudio <163354043+AEmotionStudio@users.noreply.github.com>
2026-02-09 16:12:04 +00:00
AEmotionStudio 52004b753d fix: add missing sanitization for workflow JSON in video node
The workflow JSON sent to Discord was not being sanitized for webhook URLs
and GitHub tokens. This fix adds the missing sanitize_json_for_export call.
2026-02-03 07:08:50 -08:00
Æmotion Studio 519e6025a8 Merge pull request #53 from AEmotionStudio/refactor/node-inheritance
fix: true overwrite_last for video node + webhook URL sanitization in json
2026-02-03 06:15:57 -08:00
AEmotionStudio 2c4277711a fix: add path validation to delete and extract ffmpeg args helper
- Add validate_path_is_safe() call in _try_delete_old_file for defense-in-depth
- Create _build_ffmpeg_base_args helper to eliminate duplicated ffmpeg argument construction
2026-02-03 06:03:30 -08:00
AEmotionStudio 195842c634 fix: case-insensitive path comparison and extract deletion to helper method
- Use os.path.normcase() for cross-platform case-insensitive path comparison
- Prevents accidental deletion of newly created file on Windows/macOS
- Extract duplicated 7-line deletion block to _try_delete_old_file helper method
2026-02-03 05:48:58 -08:00
AEmotionStudio 851b2ef353 fix: resolve video overwrite extension mismatch and audio naming issues
- When overwriting, create new file with correct extension for selected format
- Delete old file after successful creation to avoid orphaned files
- Use video file basename for audio file naming for consistency
- Apply fix to all code paths: PIL, VHS, and standard ffmpeg
2026-02-03 05:35:58 -08:00
AEmotionStudio 0b723ce1df fix: resolve PR review issues
- Remove redundant datetime import (use module-level datetime instead)
- Remove duplicate format parsing logic (keep only the sanitized version)
- Fix overwrite format mismatch: keep user's selected codec instead of matching existing file extension
2026-02-03 05:16:56 -08:00
AEmotionStudio 29d2c9856a fix: true overwrite_last for video node + webhook URL sanitization in JSON
- Implemented true 'overwrite last' for video node: finds most recently modified video file and overwrites it regardless of filename
- Fixed missing sanitize_json_for_export import in video_node.py
- Added sanitize_json_for_export to image_node.py for all workflow JSON exports
- Merged upstream changes: process_batched_images, validate_path_is_safe, format_ext sanitization
2026-02-03 05:02:10 -08:00
Æmotion Studio 9520576e4e Merge pull request #52 from Praecordi/fix-import
Update import statements to relative imports
2026-02-03 01:21:11 -08:00
Praecordi 13d2114df9 Update import statements to relative imports 2026-02-01 14:04:42 -06:00
Æmotion Studio fc4a3d37cd Merge pull request #51 from AEmotionStudio/refactor/node-inheritance
Update dependency requirements and improve documentation
2026-01-26 16:58:08 -08:00
AEmotionStudio 37a444993e Update dependency requirements and improve documentation
- Added Pillow and numpy to requirements-bot.txt and requirements-nodes.txt for better compatibility.
- Updated comments in requirements.txt for clarity on dependency usage.
2026-01-26 16:51:47 -08:00
Æmotion Studio 128e19a9b5 Merge pull request #49 from AEmotionStudio/perf/batch-processing-26794793800705711
⚡ Bolt: Optimize batch image processing
2026-01-23 18:47:13 -08:00
google-labs-jules[bot] d15f6ffc8c Remove unused import tensor_to_numpy_uint8 from image_node.py 2026-01-24 02:36:14 +00:00
Æmotion Studio 510279d4d7 Merge pull request #50 from AEmotionStudio/palette-improve-tooltips-14830605049253350872
🎨 Palette: Improve overwrite_last tooltips to warn about conflicting options
2026-01-23 18:34:42 -08:00
google-labs-jules[bot] 1697364e13 🎨 Palette: Improve overwrite_last tooltips
Explicitly warn users that 'overwrite_last' is negated by 'add_time'/'add_date' inputs in both image and video nodes. Also includes a specific warning for video nodes regarding Discord playback issues when disabling 'add_time'.
Updated tests to verify the presence of these warnings.
2026-01-24 01:23:56 +00:00
google-labs-jules[bot] ed2d1388ec Optimize image processing using batched tensor transfer 2026-01-24 01:19:49 +00:00
Æmotion Studio de5d753cdf Merge pull request #47 from AEmotionStudio/sentinel-symlink-fix-14452187009841973612
🛡️ Sentinel: Fix Symlink Overwrite Vulnerability
2026-01-22 18:48:22 -08:00
google-labs-jules[bot] 523fe68f6b Address PR review feedback: validation for non-existent dirs
- Updated `shared/path_utils.py`: `validate_path_is_safe` now walks up the directory tree to verify the first existing ancestor is not a symlink, preventing bypasses via non-existent intermediate directories.
- Updated `tests/test_symlink_attack.py`: Added regression test `test_non_existent_directory_symlink_bypass`.
2026-01-23 02:38:20 +00:00
google-labs-jules[bot] ad360061d7 Address PR review feedback: robust symlink validation
- Updated `shared/path_utils.py`: `validate_path_is_safe` now checks for symlinks in parent directories by verifying realpath vs abspath mismatch.
- Updated `nodes/video_node.py`: Added `validate_path_is_safe` check to the VHS format path recalculation block to prevent bypass.
- Updated `tests/test_symlink_attack.py`: Added regression tests for parent directory symlinks and VHS format bypass.
2026-01-23 02:05:40 +00:00
Æmotion Studio 98bbda1f94 Merge pull request #46 from AEmotionStudio/bolt/optimize-pil-batch-transfer-12357379419567633300
⚡ Bolt: Optimize PIL video generation with batched GPU-CPU transfer
2026-01-22 18:02:20 -08:00
Æmotion Studio c4a96e3484 Merge pull request #45 from AEmotionStudio/palette-tooltip-improvements-14445540006881476944
🎨 Palette: Tooltip improvements for safety and clarity
2026-01-22 18:01:56 -08:00
google-labs-jules[bot] 0e655a4303 Fix symlink overwrite vulnerability in custom nodes
- Implemented `validate_path_is_safe` in `shared/path_utils.py` to reject writing to symlinks.
- Applied validation in `nodes/video_node.py` and `nodes/image_node.py` before file operations.
- Added regression test `tests/test_symlink_attack.py`.
- Updated sentinel journal with new vulnerability pattern.
2026-01-23 01:37:51 +00:00
google-labs-jules[bot] ec09d32cf6 feat: optimize PIL video generation with batched GPU-CPU transfer
Uses `process_batched_images` generator in the PIL fallback path to reduce GPU-CPU transfer overhead by processing frames in batches (default 20) instead of individually.

Also adds `tests/test_pil_batch_optimization.py` to verify the batch processing logic.
2026-01-23 01:22:23 +00:00
google-labs-jules[bot] 9c8e73e578 🎨 Palette: Improve tooltips for safety and clarity
- Added safety warnings for `overwrite_last` option in Image and Video nodes.
- Clarified `resize_method` dependency in Image node tooltip.
- Added actionable instructions for `github_token` setup in Base node tooltip.
- Updated `tests/test_ux_tooltips.py` to verify new tooltip content.
2026-01-23 01:12:45 +00:00
Æmotion Studio af9936a706 Merge pull request #43 from AEmotionStudio/palette-ux-add-time-tooltip-4405143788425961441
🎨 Palette: Add critical warning to video timestamp tooltip
2026-01-21 17:58:54 -08:00
Æmotion Studio 9716a63591 Merge pull request #44 from AEmotionStudio/refactor/node-inheritance
Add traffic stats badge workflow and remove tests badge
2026-01-21 17:48:20 -08:00
AEmotionStudio 7775d0b212 Add traffic stats badge workflow and remove tests badge 2026-01-21 17:47:47 -08:00
Æmotion Studio 59c04a6b84 Merge pull request #41 from AEmotionStudio/bolt-video-processing-optimization-18182706454639532882
⚡ Bolt: Optimize video processing with batched ffmpeg writes
2026-01-21 17:36:59 -08:00
Æmotion Studio 6c4c2ebc94 Merge pull request #42 from AEmotionStudio/sentinel-security-fix-13410869919762130509
🛡️ Sentinel: Fix path traversal and harden temp files
2026-01-21 17:36:44 -08:00
google-labs-jules[bot] 89def34b23 UX: Add critical warning to video timestamp tooltip
Adds a critical warning to the `add_time` tooltip in `DiscordSendSaveVideo`
to inform users that disabling this option can cause single-frame playback
issues on Discord.

This moves the warning from the README into the UI where users make the
configuration choice, preventing potential bugs.

Includes regression test in `tests/test_ux_tooltips.py`.
2026-01-22 01:34:09 +00:00
google-labs-jules[bot] 411336a217 Fix path traversal in video node and harden temp file creation 2026-01-22 01:15:51 +00:00
google-labs-jules[bot] 8a2793e3fa ⚡ Optimize video processing by batching ffmpeg writes
- Updated `process_batched_images` to yield batched numpy arrays (N, H, W, C) for Tensor inputs instead of individual frames.
- Updated `DiscordSendSaveVideo.save_video` to write these batches directly to `ffmpeg` via `subprocess.stdin.write`.
- This reduces the number of system calls and Python loop iterations, improving performance significantly (from ~110 FPS to ~600 FPS in benchmarks).
- Handled `pbar` updates correctly for both batched and single-frame chunks.
- Ensured backward compatibility for list inputs (e.g. pingpong).
2026-01-22 01:13:46 +00:00
Æmotion Studio 194654ff1a Merge pull request #40 from AEmotionStudio/refactor/node-inheritance
Refactor/node inheritance
2026-01-21 11:06:09 -08:00
AEmotionStudio fa58cddf73 Remove GitHub Actions test workflow
Local testing is more reliable due to ComfyUI/torch dependency requirements.
CI environment cannot properly mock these dependencies.
2026-01-21 01:22:32 -08:00
AEmotionStudio 4b2a99e5f5 Skip test_save_images_sanitization when torch unavailable
This test requires real PyTorch for tensor iteration which isn't available
in CI due to module mocking. The test runs correctly in local dev with torch.
2026-01-21 01:19:35 -08:00
AEmotionStudio 766168ec1b Fix remaining CI test failures
- test_media.py: Use Python math.log2 instead of numpy to avoid mock issues
- test_image_node_sanitization.py: Patch tensor_to_numpy_uint8 and Image.fromarray
  to properly handle mocked torch tensors
2026-01-21 01:17:34 -08:00
AEmotionStudio 87112b8b2a Fix CI tests: Improve test isolation and mock handling
- Add numpy to requirements-nodes.txt
- Create conftest.py for test configuration
- Fix test_numpy_subprocess.py to import real numpy before any mocking
- Fix test_media.py to import real numpy early
- Fix test_image_node_sanitization.py to use MockTensor instead of torch.zeros
2026-01-21 00:46:02 -08:00
AEmotionStudio 73b2bfe5b1 Fix CI: Add numpy to requirements-nodes.txt 2026-01-21 00:41:04 -08:00
AEmotionStudio b3d8f9d16f Fix CI: Add Pillow to requirements-nodes.txt 2026-01-21 00:19:23 -08:00
AEmotionStudio b63dac6cad Refactor Image and Video nodes to inherit from BaseDiscordNode 2026-01-20 23:41:39 -08:00
AEmotionStudio 3ee819d042 refactor: make DiscordSendSaveImage inherit from BaseDiscordNode 2026-01-20 22:27:59 -08:00
AEmotionStudio 1ba7122694 docs: add GitHub Actions test badge to README 2026-01-20 19:02:00 -08:00
AEmotionStudio e00194e0e7 ci: add GitHub Actions test workflow 2026-01-20 19:01:07 -08:00
AEmotionStudio c74b572c38 chore: split requirements into nodes-only and bot versions 2026-01-20 19:00:23 -08:00
Æmotion Studio 5d23e30dbc Merge pull request #37 from AEmotionStudio/palette-tooltip-clarification-16066511053936262454
UX: Clarify resize_method dependency in image node tooltips
2026-01-20 18:18:21 -08:00
Æmotion Studio 7382295a76 Merge pull request #38 from AEmotionStudio/bolt-video-batch-processing-2145519241141552514
⚡ Bolt: Optimize video processing with batched tensor conversion
2026-01-20 18:17:56 -08:00
Æmotion Studio c4ef38cff3 Merge pull request #39 from AEmotionStudio/sentinel-webhook-token-leak-fix-6649537465366460291
🛡️ Sentinel: Fix webhook token leakage in error logs
2026-01-20 18:17:10 -08:00
google-labs-jules[bot] c1b1e2497c Fix: Sanitize webhook tokens from error messages
- Added `sanitize_token_from_text` helper to `shared/discord/webhook_client.py`.
- Updated `DiscordWebhookClient._send_with_retry` to sanitize `response.text` before returning it in error details.
- Updated `nodes/image_node.py` and `nodes/video_node.py` to sanitize `response.text` before printing error messages.
- Added regression test `tests/test_webhook_security.py`.

This prevents sensitive Discord webhook tokens from being leaked in ComfyUI console logs when the Discord API returns an error (e.g. 400 Bad Request) that echoes the request URL.
2026-01-21 01:26:33 +00:00