write_config() rebuilt config.ini's [default] section entirely from the startup snapshot into a fresh parser opened 'w'. Any Manager settings change therefore silently reverted values hand-edited while ComfyUI was running (the same config['default'] flags those messages tell users to edit), deleted the two read-but-never-written keys (http_channel_enabled, default_cache_as_channel_url), and erased every non-[default] section. get_config() now tracks which keys callers actually change, and write_config() re-reads config.ini and overlays only those keys plus the live preview_method. After a successful write the just-persisted keys are cleared from the tracker, so a key changed once through the UI does not stay dirty for the life of the process and re-clobber a later hand-edit of that same key on the next unrelated write. Hand-edited values, unknown keys, and foreign sections survive; CRLF sanitization still applies to every value written; an unparsable config.ini falls back to a full rewrite instead of failing every settings endpoint. configparser.read() suppresses OSError, so a config.ini that exists but cannot be read comes back as an empty parser rather than an exception, which would silently route the merge into the bootstrap branch and rewrite the file from defaults. write_config() now detects that case (the file exists but read() loaded nothing) and refuses the write with a raised error, leaving the file untouched, rather than destroying its contents while reporting success. tests/test_write_config_persistence.py pins the three loss classes (hand-edit revert, key deletion, section erasure), the settings round-trip, the persisted-key re-clobber guard, and the silent-read-failure refusal.
ComfyUI-Manager: Core Backend (glob)
This directory contains the Python backend modules that power ComfyUI-Manager, handling the core functionality of node management, downloading, security, and server operations.
Core Modules
- manager_core.py: The central implementation of management functions, handling configuration, installation, updates, and node management.
- manager_server.py: Implements server functionality and API endpoints for the web interface to interact with the backend.
- manager_downloader.py: Handles downloading operations for models, extensions, and other resources.
- manager_util.py: Provides utility functions used throughout the system.
Specialized Modules
- cm_global.py: Maintains global variables and state management across the system.
- cnr_utils.py: Helper utilities for interacting with the custom node registry (CNR).
- git_utils.py: Git-specific utilities for repository operations.
- node_package.py: Handles the packaging and installation of node extensions.
- security_check.py: Implements the multi-level security system for installation safety.
- share_3rdparty.py: Manages integration with third-party sharing platforms.
Architecture
The backend follows a modular design pattern with clear separation of concerns:
- Core Layer: Manager modules provide the primary API and business logic
- Utility Layer: Helper modules provide specialized functionality
- Integration Layer: Modules that connect to external systems
Security Model
The system implements a comprehensive security framework with multiple levels:
- Block: Highest security - blocks most remote operations
- High: Allows only specific trusted operations
- Middle: Standard security for most users
- Normal-: More permissive for advanced users
- Weak: Lowest security for development environments
Implementation Details
- The backend is designed to work seamlessly with ComfyUI
- Asynchronous task queuing is implemented for background operations
- The system supports multiple installation modes
- Error handling and risk assessment are integrated throughout the codebase
API Integration
The backend exposes a REST API via manager_server.py that enables:
- Custom node management (install, update, disable, remove)
- Model downloading and organization
- System configuration
- Snapshot management
- Workflow component handling