Commit Graph
400 Commits
Author SHA1 Message Date
Dr.Lt.Data aaed26a5a4 fix(config): merge write_config() onto disk instead of rebuilding from the startup snapshot (#3128)
write_config() rebuilt config.ini's [default] section entirely from the
startup snapshot into a fresh parser opened 'w'. Any Manager settings
change therefore silently reverted values hand-edited while ComfyUI was
running (the same config['default'] flags those messages tell users to
edit), deleted the two read-but-never-written keys (http_channel_enabled,
default_cache_as_channel_url), and erased every non-[default] section.

get_config() now tracks which keys callers actually change, and
write_config() re-reads config.ini and overlays only those keys plus the
live preview_method. After a successful write the just-persisted keys are
cleared from the tracker, so a key changed once through the UI does not
stay dirty for the life of the process and re-clobber a later hand-edit of
that same key on the next unrelated write. Hand-edited values, unknown
keys, and foreign sections survive; CRLF sanitization still applies to
every value written; an unparsable config.ini falls back to a full rewrite
instead of failing every settings endpoint.

configparser.read() suppresses OSError, so a config.ini that exists but
cannot be read comes back as an empty parser rather than an exception,
which would silently route the merge into the bootstrap branch and rewrite
the file from defaults. write_config() now detects that case (the file
exists but read() loaded nothing) and refuses the write with a raised
error, leaving the file untouched, rather than destroying its contents
while reporting success.

tests/test_write_config_persistence.py pins the three loss classes
(hand-edit revert, key deletion, section erasure), the settings
round-trip, the persisted-key re-clobber guard, and the silent-read-failure
refusal.
2026-08-14 06:31:38 +09:00
Dr.Lt.Data ffb2f03e92 fix(security-messages): state the actual gate in install-denial messages (#3128)
The install-denial diagnostics named the wrong gate, sending users to
settings that could not resolve their denial:

- SECURITY_MESSAGE_FLAG_GIT_URL / _FLAG_PIP omitted the loopback half of
  the flag-AND-loopback predicate, telling users to enable a flag that
  was often already enabled. They now state both conditions, print the
  live --listen value at every emission site, and explain that both
  values are read once at startup (stop the server, edit, then start).
- SECURITY_MESSAGE_MIDDLE_OR_BELOW instructed setting security_level to
  'middle', a value that does not exist; it now names only real values
  (any level other than 'strong': normal, normal-, weak).
- The blocked-risk arm reused SECURITY_MESSAGE_GENERAL, blaming
  security_level although no value of it can help there; it now emits a
  dedicated SECURITY_MESSAGE_BLOCKED_RISK stating this is not a
  configuration problem.
- SECURITY_MESSAGE_NORMAL_MINUS_MODEL now names its loopback-listener
  condition and the same restart guidance.
- The js/common.js dedicated-403 messages mirror the loopback clause.
2026-08-13 12:38:11 +09:00
Rvage 25f519ed0c Fix: tooltip global listener (#3114)
* remove noise

* fix: remove global tooltip listener
2026-08-02 15:08:27 +09:00
dehypnotic e634489a97 Update manager_server.py 2026-07-20 23:45:17 +02:00
Dr.Lt.Data 79dd5e2358 Merge pull request #2152 from jfcantu/main
New feature: Node Usage Analyzer
2026-07-20 20:13:04 +09:00
Dr.Lt.Data e4c5401dd5 feat(security): dedicated install flags decoupled from security_level (#2991)
* feat(security): add dedicated install flags decoupled from security_level

Gate 'install via git URL' and 'install via pip' with dedicated opt-in
boolean flags (allow_git_url_install / allow_pip_install) in config.ini
[default], fully replacing the security_level term on those surfaces
(REPLACE, not AND — a strict level no longer denies when the flag is on;
a weak level no longer allows when the flag is off).

- glob/manager_server.py: pure predicate is_dedicated_install_allowed
  (flag AND loopback, request-time args.listen); REPLACE gates at
  /customnode/install/git_url and /customnode/install/pip; batch
  unknown-URL arm routes through the same full predicate at the risky
  position (loopback term is load-bearing — the middle entry gate has
  no network-position term; the entry gate itself stays in force);
  unknown-pip in batch stays unconditionally blocked; new
  SECURITY_MESSAGE_FLAG_* denial constants name the responsible flag;
  security_403_response gains flag_token (comfyui_outdated keeps precedence)
- glob/manager_core.py: register both keys (read via get_bool default-false,
  write list, exception fallback); "true"-only truthy; restart-only activation
- js/common.js: 403 dialog copy names the responsible flag at the two
  install call sites
- README.md: security-policy docs for both flags (per-surface scope incl.
  the batch entry-gate qualifier, REPLACE decoupling, loopback bound,
  opt-in config snippet, default-deny + migration note); stale tier lists
  corrected against the actual gates
- CHANGELOG.md: opt-in migration note + accepted residual risk (flags
  bypass the forced-strong outdated-ComfyUI hardening on loopback,
  opt-in only), decoupling claim qualified for the batch entry gate

Tests: unit suite (predicate truth table, REPLACE litmus both directions,
AST binding-proofs against live handlers, subprocess-isolated config
contract) plus a real-server E2E suite that mounts the Manager-under-test
via git worktree (exact-SHA pin, detached) against a real ComfyUI and
exercises both flag surfaces and both arms — deny arms (403 + flag-naming
body/log + no install artifact), git-URL allow arm (real clone), pip allow
arm as a two-phase reservation oracle — with zero-residual self-clean.
Module skips without E2E_COMFYUI_ROOT; unit suite unaffected.

The manager-v4 branch ships the identical policy (shared invariants +
config contract); this tree uses the degraded predicate 'flag AND
loopback' (no personal_cloud-equivalent mode here).

* bump version to v3.41
2026-06-16 03:34:10 +09:00
Dr.Lt.Data 491f847bbc fix(security): harden CSRF with Content-Type gate and OpenAPI sync (#2819)
Defense-in-depth over GET→POST alone: reject the three CORS-safelisted
simple-form Content-Types (x-www-form-urlencoded, multipart/form-data,
text/plain) on 5 no-body POST handlers (snapshot/save,
manager/queue/{reset,start,update_comfyui}, manager/reboot) to block
<form method=POST> CSRF that bypasses method-only gating. Convert 10 pure
state-changing endpoints (fetch_updates, queue/{update_all,reset,start,
update_comfyui}, snapshot/{remove,restore,save}, comfyui_switch_version,
reboot) from GET to POST and split 5 config endpoints
(db_mode/preview_method/channel_url_list/policy/{component,update}) into
GET(read) + POST(write, JSON body). Emit the in_progress + done event pair
from the /manager/queue/install sync-enable fast-path so client UI
finalizes (previously only queue/start's empty worker done fired, leaving
item.restart unset and the Enable button visible after a successful enable).
Harden js/custom-nodes-manager.js completion path: await onQueueCompleted
with try/catch (surfaces silent turbogrid stale-item throws), replace the
{}.length == 0 no-op empty guard, set install_context before queue/install
to avoid a sync-completion race, wrap classList/updateCell in try/catch.
Resynchronize openapi.yaml with the converted routes (method → post, query
params → requestBody JSON schema, sibling post on 5 split endpoints).
Update 31 JS fetchApi call sites across 7 files; add
tests/test_csrf_content_type_helper.py covering 5 Content-Type cases via
aiohttp TestClient.

Reported-by: XlabAI Team of Tencent Xuanwu Lab
CVSS: 8.1 (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H)
2026-04-22 05:04:07 +09:00
Dr.Lt.Data 2007eab26d fix(security): add litellm supply chain attack detection and improve pip matching (#2731)
- Add litellm==1.82.7 and litellm==1.82.8 to blacklist (PYSEC-2026-2)
- Add ultralytics==8.3.42 to blacklist
- Replace substring matching with exact version set matching
- Remove early break to detect multiple malicious packages
2026-03-26 04:17:46 +09:00
Dr.Lt.Data f4fa394e0f fix(security): add input sanitization and path traversal protection
- Sanitize config string values to prevent CRLF injection attacks
- Add get_safe_snapshot_path() helper to validate snapshot targets
- Block path traversal attempts in remove_snapshot and restore_snapshot endpoints
- Reject targets containing /, \, .., or null characters
2026-01-08 18:29:14 +09:00
Dr.Lt.Data 10f3b6551c bump version 2026-01-08 01:22:59 +09:00
Dr.Lt.Data f4fdd51ce9 feat(preview): disable Manager preview method when ComfyUI native feature is available
- Add detection for ComfyUI PR #11261 (per-queue preview override)
- Return DISABLED status when native feature is detected
- Improve UI loading state and prevent flash of enabled state
- Add accessibility attributes and visual feedback for disabled state
- Show user notification when feature transitions to native
- Version bump to 3.39
2025-12-19 23:05:52 +09:00
John Cantu 1bdcd1bdbf Merge branch 'main' of https://github.com/jfcantu/ComfyUI-Manager 2025-12-14 18:11:34 -08:00
Dr.Lt.Data d8f111a5e3 bump version 2025-12-12 18:16:51 +09:00
ae5565ce68 ComfyUI version listing + nightly current fix (#2334)
* Improve comfyui version listing

* Fix ComfyUI semver selection and stable update

* Fix nightly current detection on default branch

* Fix: use tag_ref.name explicitly and cache get_remote_name result

- Use tag_ref.name instead of tag_ref object for checkout
- Cache get_remote_name() result to avoid duplicate calls

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Dr.Lt.Data <dr.lt.data@gmail.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2025-12-12 18:15:12 +09:00
Dr.Lt.Data 891005bcd3 fix(git): handle divergent branches safely during pull
- Use --ff-only flag to detect non-fast-forward situations
- Create backup branch before resetting divergent local branch
- Reset to remote branch when fast-forward is not possible
- Use time.strftime() instead of datetime for better compatibility
- Bump version to 3.38.2
2025-12-12 12:22:42 +09:00
Dr.Lt.Data 4249ac193a improved: display a more user-friendly message 2025-12-05 07:01:01 +09:00
Dr.Lt.Data aaed1dc3d5 feat(security): Support System User Protection API with security migration (V3.38) (#2338)
- Migrate Manager data path: default/ComfyUI-Manager → __manager
- Force security_level=strong on outdated ComfyUI (block installations)
- Auto-migrate config.ini only; backup legacy files for manual verification
- Raise weak/normal- to normal during migration
- Add /manager/startup_alerts API for UI warnings
- Differentiate 403 responses: comfyui_outdated vs security_level
- Block startup scripts execution on old ComfyUI

Requires ComfyUI v0.3.76+ for full functionality.
Backward compatible with older versions (uses legacy path).
2025-12-03 00:42:12 +09:00
Dr.Lt.Data e4a90089ab fixed: a bug where updating ComfyUI using Update: ComfyUI Stable Version did not updating ComfyUI's dependencies 2025-11-26 21:54:28 +09:00
Dr.Lt.Data aedc99cefd bump version 2025-11-11 00:42:32 +09:00
unclepomedev b32cab6e9a Fix: Gracefully handle errors during pip package enumeration (#2266) 2025-11-11 00:41:16 +09:00
Dr.Lt.Data 48ab48cc30 fixed: more complete uv support
* Previously, only `uv` installed inside a venv was properly handled. Now `uv` installed outside the venv is also supported.
* Even if `use_uv=False`, `uv` is used as a fallback when `pip` is unavailable.
* Even if `use_uv=True`, `pip` is used as a fallback when `uv` is unavailable.

https://github.com/Comfy-Org/ComfyUI-Manager/issues/2125
2025-09-17 06:28:06 +09:00
John Cantu 02aa67b541 Merge branch 'main' of https://github.com/jfcantu/ComfyUI-Manager 2025-09-14 22:52:41 -07:00
John Cantu 67d03530a3 Changes and new code for Node Usage Analyzer 2025-09-14 22:49:54 -07:00
Dr.Lt.Data 5ed6d8b202 update DB 2025-09-06 03:53:56 +09:00
Dr.Lt.Data eab6cdeee4 bump version 2025-08-11 12:48:38 +09:00
Dr.Lt.Data 4834874091 fixed: ruff check 2025-07-25 07:26:48 +09:00
Dr.Lt.Data 8759ebf200 bump version 2025-07-25 07:03:14 +09:00
YAN Wenkun d4715aebef Migrate matrix-client to matrix-nio (#2025) 2025-07-25 06:59:46 +09:00
Dr.Lt.Data 4a1e76730a fixed: security_check - robust checking
https://github.com/Comfy-Org/ComfyUI-Manager/issues/2002
2025-07-24 02:44:43 +09:00
Dr.Lt.Data 5599bb028b fixed: security_check - robust checking
https://github.com/Comfy-Org/ComfyUI-Manager/issues/2002
2025-07-24 02:38:53 +09:00
Dr.Lt.Data 552c6da0cc modified: download_url - provide more informative error messages
https://github.com/Comfy-Org/ComfyUI-Manager/issues/2016
2025-07-24 02:30:07 +09:00
Dr.Lt.Data cc6817a891 fixed: cnr_utils – fixed improper behavior of bypass_ssl
https://github.com/Comfy-Org/ComfyUI-Manager/issues/2017
2025-07-24 02:15:31 +09:00
Dr.Lt.Data 03ccce2804 fixed: cm-cli - provides pip dependency restoration using the options --pip-non-url, --pip-non-local-url, and --pip-local-url.
https://github.com/Comfy-Org/ComfyUI-Manager/issues/2008
2025-07-19 06:51:07 +09:00
Dr.Lt.Data 00f287bb63 fixed: ruff check 2025-07-12 06:15:09 +09:00
Dr.Lt.Data 785268efa6 modified: By default, do not forcefully downgrade numpy to below version 2. I believe enough of a grace period has now been given.
https://github.com/Comfy-Org/ComfyUI-Manager/issues/1981#issuecomment-3058772842
2025-07-12 06:07:10 +09:00
Bas Nijholt ad09e53f60 Remove file argument from logging.error in manager_server.py (#1977)
Otherwise this results in:
```python
TypeError: Logger._log() got an unexpected keyword argument 'file' 
```
2025-07-08 08:48:16 +09:00
Dr.Lt.Data 2595cc5ed7 bump version 2025-07-07 01:05:25 +09:00
Alexander Piskun 577314984c fix(Windows, numpy): fix for cm-cli usage (#1972) 2025-07-06 22:36:49 +09:00
Dr.Lt.Data 70139ded4a bump version 2025-07-06 13:40:50 +09:00
Alexander Piskun fce0d9e88e fix(Windows, numpy): do not use 'uv' by default (#1971) 2025-07-06 08:23:31 +09:00
Dr.Lt.Data 0daa826543 fixed: invalid default config.ini
https://github.com/Comfy-Org/ComfyUI-Manager/issues/1967
2025-07-04 17:54:26 +09:00
Dr.Lt.Data e71f3774ba modified: If uv is available, set use_uv to True by default. 2025-07-03 12:32:50 +09:00
Dr.Lt.Data 73d971bed8 bump version 2025-07-02 12:33:16 +09:00
Dr.Lt.Data a0aee41f1a fixed: Support configuration with use_uv enabled in environments where only uv exists without pip.
https://github.com/Comfy-Org/ComfyUI-Manager/issues/1828
2025-06-25 12:44:26 +09:00
Dr.Lt.Data 815784e809 fixed: Fix issue where some nodepacks were displayed redundantly in custom nodes manager. 2025-06-25 00:18:18 +09:00
Dr.Lt.Data 89710412e4 fixed: indentation error 2025-06-17 07:27:46 +09:00
Dr.Lt.Data 931973b632 update DB 2025-06-17 07:22:13 +09:00
Dr.Lt.Data 1246538bbb fixed: Issue where installation status was not properly recognized when the nodepack ID registered in the registry was not normalized.
- ex) `ComfyUI-Crystools`

https://github.com/Comfy-Org/ComfyUI-Manager/issues/1834#issuecomment-2937370214
2025-06-17 00:31:51 +09:00
Dr.Lt.Data cac105b0d5 fixed: prevent halting when log flushing fails.
https://github.com/Comfy-Org/ComfyUI-Manager/issues/1794
2025-06-08 06:54:39 +09:00
Dr.Lt.Data a3fb847773 fixed: Don't override preview method if --preview-method is given
https://github.com/Comfy-Org/ComfyUI-Manager/issues/1887
2025-06-08 06:33:42 +09:00