Vito Sansevero
0e527fd80a
fix: replace Tailwind v3 bg-opacity utilities with v4 slash syntax
...
bg-opacity-N is ignored in Tailwind v4, causing overlays to render
as solid black rectangles (hiding gallery modal images). Converted
all bg-black bg-opacity-N to bg-black/N across admin.js, gallery.js,
and gallery.html.
2026-02-08 07:06:25 -08:00
Vito Sansevero
0cb941e894
fix: move comfyui-theme.css to lib/tailwind/ for proper serving
...
The Python API only has static file routes for /prompt_manager/lib/
and /prompt_manager/js/ — no route exists for /css/. The theme CSS
was returning 404, causing all --pm-* variables to be undefined
(white/transparent rendering). Moved to lib/tailwind/ where the
existing route serves it correctly.
2026-02-08 06:53:32 -08:00
Vito Sansevero
e1f1121cb8
build: rebuild Tailwind CSS with all --pm-* token utilities
...
Recompile styles.css after Phase 2-4 changes. All custom bg-pm-*,
text-pm-*, border-pm-*, shadow-pm-*, rounded-pm-* utilities present.
2026-02-08 06:40:24 -08:00
Vito Sansevero
efe2138e4d
refactor: Phase 4 remove dark-only infrastructure
...
- Remove viewer-dark-theme class from ViewerJS init (overrides now global)
- Remove custom-scrollbar class usage (scrollbar styles now global)
- No dark: prefixes or class="dark" remain in codebase
2026-02-08 06:39:53 -08:00
Vito Sansevero
b616a26df1
style: Phase 3 typography and spacing pass
...
- Reduce heading sizes: text-xl/2xl/3xl → text-sm font-semibold
- Tighten modal padding: p-6 → p-4, px-6 py-4 → px-4 py-2
- Compact empty states: py-12 → py-6, py-8 → py-4
- Reduce space-y-6 → space-y-3 in metadata panels
- Shrink stat card numbers: text-xl → text-lg
- Shrink decorative emojis: text-2xl/3xl → text-lg
- Keep lightbox nav buttons at text-xl for usability
2026-02-08 06:39:00 -08:00
Vito Sansevero
8652bb70d6
feat: complete Phase 2 component redesign across all frontend files
...
Migrate all remaining hardcoded Tailwind color classes to --pm-* design
tokens across gallery.html, metadata.html, admin.js, gallery.js, and
tags-page.js. Zero hardcoded color classes remain in HTML/JS files.
- gallery.html: remove inline styles (now in comfyui-theme.css), strip
gradients/decorative elements, tighten spacing for ComfyUI density
- metadata.html: add theme imports, replace all color classes
- admin.js: replace 164 color occurrences in template literals, convert
raw hex values to CSS variable references
- gallery.js: replace 161 color occurrences in template literals
- tags-page.js: replace 30 color occurrences in template literals
2026-02-08 06:35:43 -08:00
Vito Sansevero
d0aa7d7080
feat: migrate to Tailwind v4 and ComfyUI theme token system
...
- Add comfyui-theme.css with --pm-* design tokens mapped to ComfyUI CSS vars
- Add theme-bridge.js for light/dark palette detection via ComfyUI API
- Migrate Tailwind from v3 to v4 (@import, @source, @utility directives)
- Remove tailwind.config.js (replaced by v4 CSS-based config)
- Begin admin.html component redesign: hardcoded colors → --pm-* tokens,
strip gradients, tighten spacing for ComfyUI-native look
Work in progress — Phase 2 (component redesign) partially complete.
2026-02-08 06:23:48 -08:00
Vito Sansevero
15bbfc4044
chore: bump project version to 3.0.34 in pyproject.toml
2026-02-08 05:40:44 -08:00
Vito
75b0ebe69c
Merge pull request #111 from ComfyAssets/fix/image-scan-directory-108
...
fix: custom image scan directory ignored due to wrong import
2026-02-08 05:40:07 -08:00
Vito Sansevero
c9ca4be8b8
fix: custom image scan directory ignored due to wrong import ( #108 )
...
start_monitoring() used an absolute import (from py.config) to read
MONITORING_DIRECTORIES, which either failed with ImportError or loaded
a separate module instance with empty defaults. The configured custom
directory was never used, and auto-detection always kicked in.
Fixed by consolidating into the single relative import (from ..py.config)
that was already used for the MONITORING_ENABLED check.
2026-02-08 05:38:42 -08:00
Vito Sansevero
7f92c4d5b8
fix: preserve full tracebacks in server-side error logging
...
Use logger.exception() and exc_info=True to retain stack traces
for debugging, addressing Codex review feedback on PR #110 .
2026-02-08 05:33:06 -08:00
Vito
28c386d529
Merge pull request #110 from ComfyAssets/fix/stack-trace-exposure
...
fix: prevent stack trace exposure in SSE error responses
2026-02-08 05:32:23 -08:00
Vito Sansevero
bb34b9cf3b
fix: use system-installed Black in pre-commit to match CI
...
Avoids version mismatch between pre-commit's pinned Black and CI's
latest Black. All hooks now use local system tools for consistency.
2026-02-08 05:30:31 -08:00
Vito Sansevero
be205f3dcc
feat: add pre-commit hooks for local CI checks
...
- Black (auto-fix formatting on commit)
- Flake8 (block on syntax errors and undefined names)
- Bandit (security scan, non-blocking to match CI)
- Tests (run on pre-push only)
- Apply Black formatting fixes caught by the new hooks
2026-02-08 05:27:03 -08:00
Vito Sansevero
ed40be066c
fix: prevent stack trace exposure in SSE error responses
...
Log exception details server-side only; send generic error messages
to clients via SSE streams to resolve code scanning alerts.
2026-02-08 05:23:04 -08:00
Vito
fb092e7c25
Merge pull request #109 from ComfyAssets/fix/security-scanning-issues
...
Fix 15 GitHub code scanning security alerts
2026-02-07 13:08:58 -08:00
Vito Sansevero
55376b4752
fix: remove unused safePrompt variable in admin.js showFullPrompt
...
textContent already treats text as literal, so the escapeHtml() call
was redundant. Removes the unused variable flagged by code quality bot.
2026-02-07 13:07:38 -08:00
Vito Sansevero
113d663fce
fix: resolve 15 GitHub code scanning security alerts
...
- Fix XSS in showFullPrompt() across admin.js, gallery.js, metadata.html
by replacing HTML string interpolation with DOM manipulation (createElement
+ textContent), eliminating unsafe user content injection
- Fix stack trace exposure in py/api error responses by replacing str(e)
with generic messages and adding logger.exception() for server-side
traceability
2026-02-07 13:04:52 -08:00
Vito
85aff0179a
Merge pull request #107 from ComfyAssets/chore/ci-cd-improvements
...
Chore/ci cd improvements
2026-02-07 12:43:49 -08:00
Vito Sansevero
15d5a9197a
style: apply Black formatting to new test files
2026-02-07 12:36:11 -08:00
Vito Sansevero
e1bf06cb3d
test: add comprehensive unit tests for validators, hashing, metadata, config, and prompt tracker
...
Adds 143 new tests across 5 files covering previously untested modules:
- test_validators.py: all 7 validator functions + edge cases
- test_hashing.py: content hash, duplicate detection
- test_metadata_extraction.py: ComfyUI PNG metadata parsing with real images
- test_config.py: GalleryConfig/PromptManagerConfig with mocked PromptServer
- test_prompt_tracker.py: thread-safe prompt tracking, timeouts, context manager
Total test count: 87 → 264
2026-02-07 12:33:48 -08:00
Vito
bbe7a4c217
Update dependabot.yml
...
updating dependabot.
2026-02-07 12:27:32 -08:00
Vito
ccedeba7ec
Create SECURITY.md
...
adding security policy
2026-02-07 12:24:54 -08:00
Vito Sansevero
fde3546574
docs: add CI status badges to README
...
License, Python version, ComfyUI compatibility, Tests, and Code Quality
badges matching KikoTools style.
2026-02-07 12:18:21 -08:00
Vito
7bcc64e0df
Merge pull request #106 from ComfyAssets/dependabot/github_actions/actions/cache-5
...
build(deps): bump actions/cache from 4 to 5
2026-02-07 12:06:59 -08:00
Vito
b799485b74
Merge pull request #105 from ComfyAssets/dependabot/github_actions/actions/setup-python-6
...
build(deps): bump actions/setup-python from 5 to 6
2026-02-07 12:06:38 -08:00
Vito
db1de5eddd
Merge pull request #104 from ComfyAssets/dependabot/github_actions/actions/checkout-6
...
build(deps): bump actions/checkout from 4 to 6
2026-02-07 12:06:09 -08:00
dependabot[bot]
2992b7809d
build(deps): bump actions/cache from 4 to 5
...
Bumps [actions/cache](https://github.com/actions/cache ) from 4 to 5.
- [Release notes](https://github.com/actions/cache/releases )
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md )
- [Commits](https://github.com/actions/cache/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: actions/cache
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-07 16:32:03 +00:00
dependabot[bot]
f7e0c9be2b
build(deps): bump actions/setup-python from 5 to 6
...
Bumps [actions/setup-python](https://github.com/actions/setup-python ) from 5 to 6.
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](https://github.com/actions/setup-python/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/setup-python
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-07 16:32:00 +00:00
dependabot[bot]
5ef0ded757
build(deps): bump actions/checkout from 4 to 6
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4...v6 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-07 16:31:55 +00:00
Vito
4054449650
Merge pull request #103 from ComfyAssets/chore/ci-cd-improvements
...
chore(ci): add code quality, Dependabot, and Black formatting
2026-02-07 08:31:16 -08:00
Vito Sansevero
2737a4b1ef
style: apply Black formatter (line-length=88) to all Python files
...
Automated formatting pass across 30 files to establish consistent code
style enforced by CI. No logic changes.
2026-02-07 08:30:09 -08:00
Vito Sansevero
224fcc7803
chore(ci): add code quality, security scanning, and Dependabot
...
- Add code-quality.yml: Black formatting check, flake8 linting, bandit
security scan
- Add dependabot.yml: weekly updates for pip deps and GitHub Actions
- Add requirements-dev.txt: single source of truth for CI dependencies
- Harden test.yml: add permissions, pip caching, use requirements-dev.txt
- Add Black/flake8/bandit config to pyproject.toml (line-length=88)
2026-02-07 08:30:00 -08:00
Vito Sansevero
5c5fe512c8
chore: bump version to 3.0.33 in pyproject.toml
2026-02-07 08:09:26 -08:00
Vito
a7a79eb75b
Merge pull request #102 from ComfyAssets/fix/phase0-quick-wins
...
fix: pre-compile Tailwind CSS, track vendor libs (#88 )
2026-02-07 08:07:39 -08:00
Vito Sansevero
2a7b53a47b
fix(ci): add missing watchdog dependency to test workflow
...
Tests importing prompt_manager.py fail in CI because watchdog (used by
image_monitor.py) isn't installed. Add it alongside Pillow and aiohttp.
2026-02-07 08:05:01 -08:00
Vito Sansevero
5b67143782
chore: gitignore local/AI tooling files and untrack prompts.db
...
Add .claude/, .serena/, .playwright-mcp/, logs/, docs/, AGENTS.md,
CLAUDE.md, standalone_tagger.py, and prompts.db to .gitignore.
Untrack prompts.db so local database changes don't pollute diffs.
2026-02-07 07:58:51 -08:00
Vito Sansevero
a17ecd02c1
fix: pre-compile Tailwind CSS and track vendor libs ( #88 )
...
Replace 398KB Tailwind Play Mode runtime (not for production) with 37KB
pre-compiled CSS. Fix .gitignore so web/lib/ vendor files (Tailwind CSS,
ViewerJS) are tracked — fresh clones were completely broken without them.
- Add gitignore negation rules for web/lib/
- Compile Tailwind v3.4.17 CSS at dev time via standalone CLI
- Replace <script> tags with <link> in admin, gallery, metadata HTML
- Delete tailwind.js runtime (no longer needed)
- Add Makefile with css/css-watch/css-setup targets for devs
- Track ViewerJS vendor files (viewer.min.js, viewer.min.css)
2026-02-07 07:57:31 -08:00
Vito Sansevero
6271d12426
test: add API integration tests and update CI dependencies
...
Add 26 aiohttp-based API endpoint tests covering health, recent prompts,
search, save/delete, update, tags, categories, stats, export, and
response envelope validation. Add aiohttp to CI workflow dependencies.
2026-02-07 07:35:59 -08:00
Vito Sansevero
45d23efcf1
test: add comprehensive database tests and CI pipeline
...
Phase 6 test infrastructure (6.1, 6.2, 6.5):
- Fix .coveragerc source path (src -> .)
- Fix pre-existing test failure (patch target + method rename)
- Add 52 database layer tests covering CRUD, junction table tags,
search, pagination, statistics, image linking, and edge cases
- Add GitHub Actions CI workflow (Python 3.10-3.12)
- Total: 61 tests, all passing
2026-02-07 07:06:54 -08:00
Vito Sansevero
4deda8542d
feat: normalize tag storage with junction tables
...
Phase 5 scalability and polish:
- Add tags + prompt_tags junction tables replacing JSON column
- Migrate existing JSON tags via json_each() on startup
- Rewrite all tag queries to use junction tables (O(1) vs O(n))
- Simplify rename/delete/merge tag operations to single SQL
- Batch-attach preview images to prompt list responses (fix N+1)
- Fix fetchone() fragility under thread contention (defensive defaults)
2026-02-07 07:02:39 -08:00
Vito Sansevero
4548beb723
refactor: split api.py into domain modules and extract frontend JS
...
Phase 4 structural refactoring:
- Split monolithic py/api.py (5.3k lines) into domain mixins:
prompts.py, images.py, admin.py, logging_routes.py, autotag_routes.py
- Extract inline JS from admin.html into web/js/admin.js
- Extract inline JS from gallery.html into web/js/gallery.js
- Add gzip compression middleware to API responses (Phase 5.4)
- Standardize API error envelope with success: false (Phase 5.3)
- Add filmstrip image enrichment to prompt list responses (Phase 5.2)
2026-02-07 07:02:25 -08:00
Vito Sansevero
4f62066c63
fix: harden nodes, validators, and utility modules
...
Phase 0-3 fixes from codebase audit:
- Extract shared node logic into prompt_manager_base.py (DRY)
- Add input validation guards to validators.py
- Fix logging_config.py buffer management
- Harden image_monitor.py against race conditions
- Fix prompt_tracker.py cleanup edge cases
- Fix diagnostics.py import path
- Wire config.py server instance correctly
2026-02-07 07:02:10 -08:00
Vito
3e3a457fda
Merge pull request #100 from ComfyAssets/feature/tagger
...
Feature/tagger
2026-02-06 14:36:17 -08:00
Vito Sansevero
091689f9f5
chore: bump version to 3.0.32 in pyproject.toml
2026-02-06 14:34:00 -08:00
Vito Sansevero
bd6c136608
refactor(tags-page): improve code structure and reuse
2026-02-06 14:33:26 -08:00
Vito Sansevero
af9ee4e671
feat(web): add load more prompts button
2026-02-06 14:33:10 -08:00
Vito Sansevero
6ef040b4b8
refactor(comfyui): remove class_type conversion logic
2026-02-06 14:32:55 -08:00
Vito Sansevero
a5a1169829
fix(api): handle invalid input and improve progress tracking
2026-02-06 14:32:43 -08:00
Vito Sansevero
9e337ed02a
fix(database): handle skipped prompts in tag operations
2026-02-06 14:32:01 -08:00