security: exclude api_token from IS_CHANGED hash to fix CodeQL warning
The api_token is sensitive data and shouldn't be included in the SHA256 hash. The hash is only used for ComfyUI cache invalidation, where the URL change is sufficient to trigger re-execution. Including the token was unnecessary and triggered a security warning. This fixes the CodeQL alert: py/weak-sensitive-data-hashing
This commit is contained in:
@@ -144,10 +144,10 @@ class ModelDownloaderNode(ComfyAssetsBaseNode):
|
||||
import time
|
||||
import hashlib
|
||||
|
||||
# Create a unique hash based on inputs and current time
|
||||
input_str = (
|
||||
f"{url}|{save_path}|{filename}|{api_token}|{force_download}|{time.time()}"
|
||||
)
|
||||
# Create a unique hash based on non-sensitive inputs and current time
|
||||
# Note: api_token is excluded to avoid sensitive data in hash
|
||||
# The token doesn't affect cache invalidation - URL changes are sufficient
|
||||
input_str = f"{url}|{save_path}|{filename}|{force_download}|{time.time()}"
|
||||
return hashlib.sha256(input_str.encode()).hexdigest()
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user