Commit Graph
98 Commits
Author SHA1 Message Date
Vito Sansevero 2467dff704 feat(timer): add real-time workflow execution timer 2025-12-21 06:45:24 -08:00
Vito Sansevero f12debe729 chore: update image paths in selections.json 2025-12-21 06:44:49 -08:00
Vito Sansevero c64e835d2e chore(local_image_loader): update config paths 2025-12-21 06:44:38 -08:00
Vito Sansevero 36d37db8a9 feat(init): add KikoWorkflowTimerNode to mappings 2025-12-21 06:44:24 -08:00
Vito Sansevero 8c0b89ff70 style(node): Reformat code for readability 2025-12-17 07:06:16 -08:00
Vito Sansevero 14738b80c5 feat(image_loader): add directory listing API endpoint 2025-12-17 07:01:55 -08:00
Vito Sansevero bff1276d06 style: Add newline at EOF in JSON file 2025-12-17 07:01:46 -08:00
Vito Sansevero a7805ad587 feat: add WidthHeightToVec2Node to mappings 2025-12-17 07:01:34 -08:00
Vito Sansevero 6368582e1b feat: Add WidthHeightToVec2Node with tests 2025-12-17 06:59:11 -08:00
Vito Sansevero 498fae1211 feat(image_loader): add search_files function 2025-11-14 13:05:52 -08:00
Vito Sansevero d24912036c chore(local_image_loader): update last_path in config.json 2025-11-14 13:05:52 -08:00
Vito Sansevero f8210d8f69 feat(presets): Add new SDXL portrait and landscape presets 2025-10-18 12:46:31 -07:00
Vito Sansevero aceb34b9b0 feat(seed_history): add seed mode handling and validation 2025-10-18 12:46:19 -07:00
Vito Sansevero e9ce1fd2cf feat(model_downloader): handle download interruption 2025-10-18 12:45:46 -07:00
Vito Sansevero 9b888443ac feat(model_downloader): add interrupt handling 2025-10-18 12:45:37 -07:00
Vito Sansevero f4743df3ef feat(model_downloader): add cancel download support 2025-10-18 12:45:27 -07:00
Vito Sansevero 6a68983ef4 feat(model_downloader): Add interrupt check support 2025-10-18 12:45:09 -07:00
Vito Sansevero fb01fa24ae chore: update selections.json with new images 2025-10-18 12:44:43 -07:00
Vito Sansevero 65f68f59a1 chore: update last_path in config.json 2025-10-18 12:44:12 -07:00
Vito Sansevero a1625dddad refactor(node): simplify sampler return logic 2025-10-07 07:20:58 -07:00
Vito Sansevero a88232f59a refactor(compact_node): simplify sampler return logic 2025-10-07 07:20:47 -07:00
Vito Sansevero 6746b86685 feat(kiko_save_image): add persistent counter for filenames 2025-10-07 07:20:35 -07:00
Vito Sansevero 8399fad96b fix: prevent URL substring sanitization bypass attacks
Fixed incomplete URL substring sanitization vulnerability (CodeQL alert)
by implementing proper domain validation using urlparse().netloc instead
of substring checking with 'in url'.

Changes:
- civitai.py: Added explicit domain validation before processing URLs
  - Only allow exact matches: 'civitai.com' and 'www.civitai.com'
  - Reject URLs like 'evil.com/civitai.com' or 'civitai.com.evil.com'

- detector.py: Improved URL detection methods
  - _is_civitai_url: Changed from 'in parsed.netloc' to exact match
  - _is_huggingface_url: Added allowlist of valid HF domains
    - Supports: huggingface.co, www.huggingface.co, cdn.huggingface.co,
      cdn-lfs.huggingface.co

Security Impact:
Prevents subdomain attacks and URL smuggling where malicious URLs could
bypass validation by including legitimate domain names as substrings:
- https://evil.com/civitai.com/malicious
- https://civitai.com.evil.com/models/123
- https://subdomain.civitai.com/attack

All security tests pass with 100% malicious URL rejection rate.
2025-10-05 07:32:18 -07:00
Vito Sansevero e00406747f security: exclude api_token from IS_CHANGED hash to fix CodeQL warning
The api_token is sensitive data and shouldn't be included in the SHA256
hash. The hash is only used for ComfyUI cache invalidation, where the
URL change is sufficient to trigger re-execution. Including the token
was unnecessary and triggered a security warning.

This fixes the CodeQL alert: py/weak-sensitive-data-hashing
2025-10-05 07:24:46 -07:00
VitoandCopilot Autofix powered by AI a21e677629 Potential fix for code scanning alert no. 14: Use of a broken or weak cryptographic hashing algorithm on sensitive data
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2025-10-05 07:18:17 -07:00
Vito Sansevero 0a6ee72748 fix: replace LatentBatch import with local implementation for V3 schema compatibility
Refs #43

ComfyUI is converting nodes_latent.py to V3 Schema on October 8th, which will
break direct imports of LatentBatch. This commit replaces the import with a
local implementation copied directly from ComfyUI source code.

Changes:
- Removed: from comfy_extras.nodes_latent import LatentBatch
- Added: Local batch_latents() and reshape_latent_to() functions
- Updated: latentbatch.batch() calls to use batch_latents()
- Added: torch and comfy.utils imports for tensor operations
- Added: Comprehensive unit tests for latent batching functionality

The local implementation is functionally identical to the original and ensures
the node will continue working after the V3 schema migration.

Test Coverage:
- 5 new tests in TestLatentBatchingFunctions class
- All 16 tests passing (11 existing + 5 new)
- Tests cover tensor operations, batch indexing, and reshape logic
2025-10-05 06:08:21 -07:00
Vito Sansevero 51bb7711b8 feat(init): add ModelDownloader and TextInput nodes 2025-10-05 05:39:35 -07:00
Vito Sansevero 8f459c502a feat(model_downloader): add model downloaders tool 2025-10-05 05:39:21 -07:00
Vito Sansevero af1bc6845a feat(text_input): add text input tool for ComfyUI 2025-10-05 05:39:09 -07:00
Vito Sansevero 04218704b3 feat(presets): add Qwen presets and categories 2025-09-23 07:22:53 -07:00
Vito Sansevero 5f6846c3cb style(core): remove unused imports and adjust formatting 2025-08-27 09:44:16 -07:00
Vito Sansevero 2e1f563298 feat(local_image_loader): add local image loader tool 2025-08-27 09:31:07 -07:00
Vito Sansevero 4b63cb7176 feat(batch_prompts): add batch prompt processing node 2025-08-27 09:30:43 -07:00
Vito Sansevero c6b5dc4b54 feat(init): add BatchPrompts and LocalImageLoader nodes 2025-08-27 09:29:02 -07:00
Vito Sansevero e6c8dd583f fix: convert Empty Latent Batch swap button from canvas to DOM widget
- Switch from unreliable canvas-based drawing to DOM widget approach
- Eliminate coordinate calculation complexity and mouse position issues
- Use same proven pattern as Seed History node buttons
- Add proper hover/click animations and visual feedback
- Fix callback bug in heightWidget.callback assignment
- Remove all canvas drawing, mouse handling, and coordinate code
- Button now works consistently without coordinate system problems

Resolves swap button not working issue by using reliable DOM elements
instead of manual canvas coordinate calculations.
2025-08-19 11:48:53 -07:00
Vito Sansevero d2b30f0a78 feat: Add auto-batching support for large LoRA collections
- Add auto-batching functionality to split large LoRA collections into manageable chunks
- Implement batch_size parameter to control number of LoRAs per batch (default: 25)
- Add batch_index parameter to select which batch to process
- Include batch tracking metadata in LORA_PARAMS for visualization
- Display batch info in plot parameters when available
- Update lora_list output to show batch header when auto-batching is enabled
- Add comprehensive tests for batching functionality
- Update documentation with detailed auto-batching usage instructions

This feature prevents UI disconnection issues when processing large numbers of LoRAs
by allowing users to process them in smaller batches sequentially.
2025-08-16 17:27:59 -07:00
Vito Sansevero b95bf8e64a refactor: Remove custom CFG slider display in Sampler Combo nodes
- Remove "display": "slider" parameter from CFG input in SamplerComboNode
- Remove "display": "slider" parameter from CFG input in SamplerComboCompactNode
- Both nodes now use ComfyUI's standard float input instead of custom slider
- All tests passing (354 unit tests)
2025-08-14 19:06:44 -07:00
Vito Sansevero 90e4b57dc6 style: add missing newline to any_type.py for black formatting 2025-08-10 06:33:12 -07:00
Vito Sansevero 386e48c2e1 feat: add Kiko Purge VRAM node for intelligent memory management
- Add comprehensive VRAM management tool with 4 purge modes (soft, aggressive, models_only, cache_only)
- Implement smart memory threshold triggering to avoid unnecessary purges
- Add detailed memory reporting showing before/after stats and freed MB
- Support passthrough design for seamless workflow integration
- Include graceful CPU fallback for non-CUDA environments
- Add comprehensive test suite with 14 tests covering all functionality
- Update documentation with detailed usage examples and parameters
- Create reusable AnyType class for wildcard input matching

The node provides essential memory management capabilities for complex workflows,
helping prevent OOM errors and optimize multi-model processing pipelines.
2025-08-10 06:25:48 -07:00
Vito Sansevero 624ba92723 feat: add Kiko Purge VRAM node for intelligent memory management
- Add comprehensive VRAM management tool with 4 purge modes (soft, aggressive, models_only, cache_only)
- Implement smart memory threshold triggering to avoid unnecessary purges
- Add detailed memory reporting showing before/after stats and freed MB
- Support passthrough design for seamless workflow integration
- Include graceful CPU fallback for non-CUDA environments
- Add comprehensive test suite with 14 tests covering all functionality
- Update documentation with detailed usage examples and parameters
- Create reusable AnyType class for wildcard input matching

The node provides essential memory management capabilities for complex workflows,
helping prevent OOM errors and optimize multi-model processing pipelines.
2025-08-10 06:17:42 -07:00
Vito Sansevero ca9fd5153a style(kikotools): Update category names and refactor nodes 2025-08-08 21:01:48 -07:00
Vito Sansevero 80045954a5 refactor(node): handle missing folder_paths module 2025-08-08 18:07:38 -07:00
Vito Sansevero 576efbba41 feat: complete embedding autocomplete implementation with all features
- Remove debug code and console.log statements
- Fix test suite to properly mock folder_paths module
- Update test expectations to match actual implementation
- Add comprehensive README documentation with feature list
- Add placeholder images for documentation screenshots
- Include diagnostic scripts for testing embedding paths
- All tests passing (338 passed, 2 skipped)

Features implemented:
- Autocomplete for embeddings, LoRAs, and custom tags
- Custom word list loading from URL (with security validation)
- Configurable triggers and settings
- Auto-insert comma, replace underscores, Tab/Enter selection
- Smart scrolling in suggestion list
- Secure content validation to prevent XSS attacks

Credits to pythongosssss/ComfyUI-Custom-Scripts for inspiration
2025-08-08 17:45:21 -07:00
Vito Sansevero 05a9520436 debug: add comprehensive logging to diagnose autocomplete issues
- Add console logging to JS for resource fetching and widget attachment
- Add debug mode with window.kikoDebug for inspection
- Log Python API endpoint registration and file discovery
- Track widget creation and event handling
- Show first 5 items when loading resources
2025-08-08 15:00:28 -07:00
Vito Sansevero 40b91fc44f feat: enhance embedding autocomplete with interactive test panel
- Add debug/test panel to the node with helpful usage hints
- Display counts of available embeddings and LoRAs
- Show sample items and status information
- Include clear instructions for triggering autocomplete
- Update display name with 🫶 branding
- Make node an OUTPUT_NODE to display information
2025-08-08 13:58:45 -07:00
Vito Sansevero 3e7734bbc3 feat: add KikoEmbeddingAutocomplete with settings registry system
- Implement centralized settings registry for all KikoTools
- Create KikoEmbeddingAutocomplete node with backend API
- Add frontend JavaScript autocomplete widget with ComfyUI integration
- Support for embeddings and LoRAs with smart filtering
- Configurable settings in ComfyUI UI with 🫶 branding
- Include keyboard navigation and real-time suggestions
2025-08-08 13:20:09 -07:00
Vito Sansevero 0f79601065 feat: add KikoFilmGrain node for realistic film grain effects
- Implement film grain effect with customizable parameters (scale, strength, saturation, toe, seed)
- Use pure PyTorch operations for better GPU utilization (no OpenCV dependencies)
- Apply ITU-R BT.709 color space conversion for accurate grain distribution
- Implement screen blend mode for better highlight preservation
- Add channel-specific weighting matching real film characteristics (3x blue, 2x red)
- Preserve alpha channel when present
- Add comprehensive test suite (20 tests covering all functionality)
- Include documentation and example workflow
- Register node under ComfyAssets/image category

Improvements over reference implementation:
- More efficient memory management avoiding numpy/OpenCV conversions
- Better grain mixing algorithm with proper color science
- Improved performance through PyTorch-native operations
2025-08-07 18:42:37 -07:00
Vito Sansevero 5485aa8c19 feat(xyz-helpers): add ComfyUI_essentials nodes adaptation
BREAKING CHANGE: Node categories now use emoji-based organization

Add 6 new xyz-helper nodes adapted from comfyui-essentials-nodes:
- FluxSamplerParams: FLUX-optimized parameter generator with batch support
- LoRAFolderBatch: Batch process multiple LoRAs from folders
- PlotParameters: Visualize parameter effects with graphs
- SamplerSelectHelper: Intelligent sampler selection with recommendations
- SchedulerSelectHelper: Optimal scheduler selection for samplers
- TextEncodeSamplerParams: Combined text encoding and parameter management

Changes:
- Port and enhance nodes from comfyui-essentials (now in maintenance mode)
- Add comprehensive documentation with attribution to original author (cubiq)
- Create example workflows for xyz-helpers tools
- Update all node categories to use emoji-based organization
- Fix all unit tests to pass with new category system
- Update README with xyz-helpers section and attribution

Attribution: xyz-helpers adapted from github.com/cubiq/ComfyUI_essentials

All tests passing (318 pass, 2 skip)
2025-08-07 05:41:23 -07:00
Vito Sansevero 9fd80793db feat(init): add ImageScaleDownByNode support 2025-08-04 10:35:54 -07:00
Vito Sansevero 972c487dd4 Add image_scale_down_by tool and display_any.js
- Add new image_scale_down_by tool for downscaling images/latents
- Add display_any.js web component for node display
- Include comprehensive unit tests for the new tool
2025-08-04 07:17:55 -07:00