security: exclude api_token from IS_CHANGED hash to fix CodeQL warning

The api_token is sensitive data and shouldn't be included in the SHA256
hash. The hash is only used for ComfyUI cache invalidation, where the
URL change is sufficient to trigger re-execution. Including the token
was unnecessary and triggered a security warning.

This fixes the CodeQL alert: py/weak-sensitive-data-hashing
This commit is contained in:
Vito Sansevero
2025-10-05 07:24:46 -07:00
parent a21e677629
commit e00406747f
+4 -4
View File
@@ -144,10 +144,10 @@ class ModelDownloaderNode(ComfyAssetsBaseNode):
import time
import hashlib
# Create a unique hash based on inputs and current time
input_str = (
f"{url}|{save_path}|{filename}|{api_token}|{force_download}|{time.time()}"
)
# Create a unique hash based on non-sensitive inputs and current time
# Note: api_token is excluded to avoid sensitive data in hash
# The token doesn't affect cache invalidation - URL changes are sufficient
input_str = f"{url}|{save_path}|{filename}|{force_download}|{time.time()}"
return hashlib.sha256(input_str.encode()).hexdigest()