From e00406747f83c58e81db7e7e7ed0008b88bc2b4e Mon Sep 17 00:00:00 2001 From: Vito Sansevero Date: Sun, 5 Oct 2025 07:24:46 -0700 Subject: [PATCH] security: exclude api_token from IS_CHANGED hash to fix CodeQL warning The api_token is sensitive data and shouldn't be included in the SHA256 hash. The hash is only used for ComfyUI cache invalidation, where the URL change is sufficient to trigger re-execution. Including the token was unnecessary and triggered a security warning. This fixes the CodeQL alert: py/weak-sensitive-data-hashing --- kikotools/tools/model_downloader/node.py | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/kikotools/tools/model_downloader/node.py b/kikotools/tools/model_downloader/node.py index 61cc493..e6032ac 100644 --- a/kikotools/tools/model_downloader/node.py +++ b/kikotools/tools/model_downloader/node.py @@ -144,10 +144,10 @@ class ModelDownloaderNode(ComfyAssetsBaseNode): import time import hashlib - # Create a unique hash based on inputs and current time - input_str = ( - f"{url}|{save_path}|{filename}|{api_token}|{force_download}|{time.time()}" - ) + # Create a unique hash based on non-sensitive inputs and current time + # Note: api_token is excluded to avoid sensitive data in hash + # The token doesn't affect cache invalidation - URL changes are sufficient + input_str = f"{url}|{save_path}|{filename}|{force_download}|{time.time()}" return hashlib.sha256(input_str.encode()).hexdigest()