Commit Graph
296 Commits
Author SHA1 Message Date
Vito Sansevero 20270d9501 test: Add unit tests for KikoWorkflowTimerNode 2025-12-21 06:45:35 -08:00
Vito Sansevero 2467dff704 feat(timer): add real-time workflow execution timer 2025-12-21 06:45:24 -08:00
Vito Sansevero cecd1e01e9 feat(timer): add Sketch-style color picker widget 2025-12-21 06:45:10 -08:00
Vito Sansevero e504f314aa chore: bump version to 1.0.28 in pyproject.toml 2025-12-21 06:45:00 -08:00
Vito Sansevero f12debe729 chore: update image paths in selections.json 2025-12-21 06:44:49 -08:00
Vito Sansevero c64e835d2e chore(local_image_loader): update config paths 2025-12-21 06:44:38 -08:00
Vito Sansevero 36d37db8a9 feat(init): add KikoWorkflowTimerNode to mappings 2025-12-21 06:44:24 -08:00
Vito Sansevero 969fd9e25e docs: Add Workflow Timer section to README.md 2025-12-21 06:44:14 -08:00
Vito Sansevero 6916b47a89 chore: bump version to 1.0.27 in pyproject.toml 2025-12-17 07:15:01 -08:00
Vito Sansevero 8c0b89ff70 style(node): Reformat code for readability 2025-12-17 07:06:16 -08:00
Vito Sansevero b527635254 test: update return types in test_assertion 2025-12-17 07:02:08 -08:00
Vito Sansevero 14738b80c5 feat(image_loader): add directory listing API endpoint 2025-12-17 07:01:55 -08:00
Vito Sansevero bff1276d06 style: Add newline at EOF in JSON file 2025-12-17 07:01:46 -08:00
Vito Sansevero a7805ad587 feat: add WidthHeightToVec2Node to mappings 2025-12-17 07:01:34 -08:00
Vito Sansevero f2093d6567 style(docs): Ensure newline at EOF in markdown files 2025-12-17 07:01:22 -08:00
Vito Sansevero 0e26f0ad36 style: Remove trailing spaces in config files 2025-12-17 07:00:53 -08:00
Vito Sansevero 9a05f20790 style: Remove unnecessary whitespace for consistency 2025-12-17 07:00:31 -08:00
Vito Sansevero 6368582e1b feat: Add WidthHeightToVec2Node with tests 2025-12-17 06:59:11 -08:00
Vito Sansevero 498fae1211 feat(image_loader): add search_files function 2025-11-14 13:05:52 -08:00
Vito Sansevero d24912036c chore(local_image_loader): update last_path in config.json 2025-11-14 13:05:52 -08:00
Vito 523b0509f1 Update pyproject.toml 2025-11-12 08:23:11 -08:00
Vito 5f8117aa56 Merge pull request #49 from wzgrx/patch-1
Update requirements.txt
2025-11-12 08:22:31 -08:00
wzgrx 22dc975353 Update requirements.txt 2025-10-25 22:05:14 +08:00
Vito Sansevero 66afb2b204 chore: bump version to 1.0.25 in pyproject.toml 2025-10-18 13:09:46 -07:00
Vito 1dd1dcf895 Merge pull request #48 from ComfyAssets/feature/downloader
Feature/downloader
2025-10-18 13:08:00 -07:00
Vito Sansevero 60f30b068e docs: add Model Downloader to README.md 2025-10-18 12:59:40 -07:00
Vito Sansevero 1439270fe5 refactor: Reorder pendingFetches initialization 2025-10-18 12:59:32 -07:00
Vito Sansevero f8210d8f69 feat(presets): Add new SDXL portrait and landscape presets 2025-10-18 12:46:31 -07:00
Vito Sansevero aceb34b9b0 feat(seed_history): add seed mode handling and validation 2025-10-18 12:46:19 -07:00
Vito Sansevero e9ce1fd2cf feat(model_downloader): handle download interruption 2025-10-18 12:45:46 -07:00
Vito Sansevero 9b888443ac feat(model_downloader): add interrupt handling 2025-10-18 12:45:37 -07:00
Vito Sansevero f4743df3ef feat(model_downloader): add cancel download support 2025-10-18 12:45:27 -07:00
Vito Sansevero 6a68983ef4 feat(model_downloader): Add interrupt check support 2025-10-18 12:45:09 -07:00
Vito Sansevero fb01fa24ae chore: update selections.json with new images 2025-10-18 12:44:43 -07:00
Vito Sansevero 65f68f59a1 chore: update last_path in config.json 2025-10-18 12:44:12 -07:00
Vito c3fab5581b Merge pull request #47 from ComfyAssets/bugs/fix-save-and-sampler
Bugs/fix save and sampler
2025-10-07 07:34:30 -07:00
Vito Sansevero 1ea2b4cc90 fix(ci): update Sampler Combo test to match SAMPLERS list return type 2025-10-07 07:28:19 -07:00
Vito Sansevero f33f39f134 chore: update .gitignore with .serena entry 2025-10-07 07:22:01 -07:00
Vito Sansevero 5b57d4fc35 test: Add tests for image counter functionality 2025-10-07 07:21:09 -07:00
Vito Sansevero a1625dddad refactor(node): simplify sampler return logic 2025-10-07 07:20:58 -07:00
Vito Sansevero a88232f59a refactor(compact_node): simplify sampler return logic 2025-10-07 07:20:47 -07:00
Vito Sansevero 6746b86685 feat(kiko_save_image): add persistent counter for filenames 2025-10-07 07:20:35 -07:00
Vito Sansevero 17af18d397 chore: bump version to 1.0.24 in pyproject.toml 2025-10-05 07:42:43 -07:00
Vito 703989599d Merge pull request #46 from ComfyAssets/alert-autofix-14
Potential fix for code scanning alert no. 14: Use of a broken or weak cryptographic hashing algorithm on sensitive data
2025-10-05 07:42:14 -07:00
Vito Sansevero 8399fad96b fix: prevent URL substring sanitization bypass attacks
Fixed incomplete URL substring sanitization vulnerability (CodeQL alert)
by implementing proper domain validation using urlparse().netloc instead
of substring checking with 'in url'.

Changes:
- civitai.py: Added explicit domain validation before processing URLs
  - Only allow exact matches: 'civitai.com' and 'www.civitai.com'
  - Reject URLs like 'evil.com/civitai.com' or 'civitai.com.evil.com'

- detector.py: Improved URL detection methods
  - _is_civitai_url: Changed from 'in parsed.netloc' to exact match
  - _is_huggingface_url: Added allowlist of valid HF domains
    - Supports: huggingface.co, www.huggingface.co, cdn.huggingface.co,
      cdn-lfs.huggingface.co

Security Impact:
Prevents subdomain attacks and URL smuggling where malicious URLs could
bypass validation by including legitimate domain names as substrings:
- https://evil.com/civitai.com/malicious
- https://civitai.com.evil.com/models/123
- https://subdomain.civitai.com/attack

All security tests pass with 100% malicious URL rejection rate.
2025-10-05 07:32:18 -07:00
Vito Sansevero 0c69abc829 fix: improve regex pattern to detect script tag bypass attempts
Improved the HTML filtering regex to properly detect all variations of
script tags including bypass attempts with whitespace before the closing
bracket (e.g., '<script >' and '</script >').

Changed from word boundary pattern /<script\b/gi to a more comprehensive
pattern /<\s*\/?script[^>]*>/gi that matches:
- Optional whitespace after opening bracket
- Optional forward slash for closing tags
- Any characters until closing bracket (catches attributes and whitespace)

This fixes the CodeQL security alert for bad HTML filtering regexp that
could be bypassed with malformed tags.

Also updated iframe, embed, and object tag patterns for consistency.
2025-10-05 07:29:41 -07:00
Vito Sansevero e00406747f security: exclude api_token from IS_CHANGED hash to fix CodeQL warning
The api_token is sensitive data and shouldn't be included in the SHA256
hash. The hash is only used for ComfyUI cache invalidation, where the
URL change is sufficient to trigger re-execution. Including the token
was unnecessary and triggered a security warning.

This fixes the CodeQL alert: py/weak-sensitive-data-hashing
2025-10-05 07:24:46 -07:00
VitoandCopilot Autofix powered by AI a21e677629 Potential fix for code scanning alert no. 14: Use of a broken or weak cryptographic hashing algorithm on sensitive data
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2025-10-05 07:18:17 -07:00
Vito 13e425959b Merge pull request #45 from ComfyAssets/fix/nodes-latent-v3-schema
fix: replace LatentBatch import with local implementation for V3 sche…
2025-10-05 06:14:12 -07:00
Vito Sansevero 0a6ee72748 fix: replace LatentBatch import with local implementation for V3 schema compatibility
Refs #43

ComfyUI is converting nodes_latent.py to V3 Schema on October 8th, which will
break direct imports of LatentBatch. This commit replaces the import with a
local implementation copied directly from ComfyUI source code.

Changes:
- Removed: from comfy_extras.nodes_latent import LatentBatch
- Added: Local batch_latents() and reshape_latent_to() functions
- Updated: latentbatch.batch() calls to use batch_latents()
- Added: torch and comfy.utils imports for tensor operations
- Added: Comprehensive unit tests for latent batching functionality

The local implementation is functionally identical to the original and ensures
the node will continue working after the V3 schema migration.

Test Coverage:
- 5 new tests in TestLatentBatchingFunctions class
- All 16 tests passing (11 existing + 5 new)
- Tests cover tensor operations, batch indexing, and reshape logic
2025-10-05 06:08:21 -07:00