Improved the HTML filtering regex to properly detect all variations of
script tags including bypass attempts with whitespace before the closing
bracket (e.g., '<script >' and '</script >').
Changed from word boundary pattern /<script\b/gi to a more comprehensive
pattern /<\s*\/?script[^>]*>/gi that matches:
- Optional whitespace after opening bracket
- Optional forward slash for closing tags
- Any characters until closing bracket (catches attributes and whitespace)
This fixes the CodeQL security alert for bad HTML filtering regexp that
could be bypassed with malformed tags.
Also updated iframe, embed, and object tag patterns for consistency.
- Remove debug code and console.log statements
- Fix test suite to properly mock folder_paths module
- Update test expectations to match actual implementation
- Add comprehensive README documentation with feature list
- Add placeholder images for documentation screenshots
- Include diagnostic scripts for testing embedding paths
- All tests passing (338 passed, 2 skipped)
Features implemented:
- Autocomplete for embeddings, LoRAs, and custom tags
- Custom word list loading from URL (with security validation)
- Configurable triggers and settings
- Auto-insert comma, replace underscores, Tab/Enter selection
- Smart scrolling in suggestion list
- Secure content validation to prevent XSS attacks
Credits to pythongosssss/ComfyUI-Custom-Scripts for inspiration
- Accept both singular and plural forms
- Common user expectation to use plural
- Regex pattern now matches embeddings?:
- Works with 120 loaded embeddings
- Extract embedding names from file_name property
- Filter out null/undefined entries
- Successfully processes 120 embeddings with proper names
- Cleaner extraction logic based on actual API response structure
- Try api.getEmbeddings(page) for pagination
- Add better logging to see item format
- Gracefully fall back to first page if pagination fails
- Log sample items to understand structure
- Detect and parse paginated response format (items array)
- Fetch all pages to get complete embeddings list (113 total)
- Support both paginated and object formats for compatibility
- Extract actual embedding names from items array
- Debug shows successful trigger detection for 'embedding:'
- Parse embeddings from object keys instead of expecting array
- Remove file extensions from embedding names
- Add fallback method for LoRAs using /object_info API
- Delay widget attachment to catch dynamically created widgets
- Better detection of textarea widgets regardless of type
- Add console logging to JS for resource fetching and widget attachment
- Add debug mode with window.kikoDebug for inspection
- Log Python API endpoint registration and file discovery
- Track widget creation and event handling
- Show first 5 items when loading resources
- Use ComfyUI's native api.getEmbeddings() for proper embedding detection
- Add dedicated /kikotools/autocomplete/loras endpoint for LoRA files
- Improve trigger detection for "embedding:" and "<lora:" patterns
- Context-aware suggestions based on trigger type
- Better insertion logic that maintains correct syntax
- Sort suggestions by relevance (exact match, starts with, alphabetical)
- Fix character matching patterns to include underscores and hyphens
- Add debug/test panel to the node with helpful usage hints
- Display counts of available embeddings and LoRAs
- Show sample items and status information
- Include clear instructions for triggering autocomplete
- Update display name with 🫶 branding
- Make node an OUTPUT_NODE to display information