- Fix XSS in showFullPrompt() across admin.js, gallery.js, metadata.html
by replacing HTML string interpolation with DOM manipulation (createElement
+ textContent), eliminating unsafe user content injection
- Fix stack trace exposure in py/api error responses by replacing str(e)
with generic messages and adding logger.exception() for server-side
traceability
- Add code-quality.yml: Black formatting check, flake8 linting, bandit
security scan
- Add dependabot.yml: weekly updates for pip deps and GitHub Actions
- Add requirements-dev.txt: single source of truth for CI dependencies
- Harden test.yml: add permissions, pip caching, use requirements-dev.txt
- Add Black/flake8/bandit config to pyproject.toml (line-length=88)
Replace 398KB Tailwind Play Mode runtime (not for production) with 37KB
pre-compiled CSS. Fix .gitignore so web/lib/ vendor files (Tailwind CSS,
ViewerJS) are tracked — fresh clones were completely broken without them.
- Add gitignore negation rules for web/lib/
- Compile Tailwind v3.4.17 CSS at dev time via standalone CLI
- Replace <script> tags with <link> in admin, gallery, metadata HTML
- Delete tailwind.js runtime (no longer needed)
- Add Makefile with css/css-watch/css-setup targets for devs
- Track ViewerJS vendor files (viewer.min.js, viewer.min.css)
Phase 5 scalability and polish:
- Add tags + prompt_tags junction tables replacing JSON column
- Migrate existing JSON tags via json_each() on startup
- Rewrite all tag queries to use junction tables (O(1) vs O(n))
- Simplify rename/delete/merge tag operations to single SQL
- Batch-attach preview images to prompt list responses (fix N+1)
- Fix fetchone() fragility under thread contention (defensive defaults)
- Fix AttributeError: 'str' has no attribute 'as_posix' on thumbnail_rel_path
in get_output_images and find_duplicates (thumbnail_rel_path is already a
string from f-string construction, not a Path object)
- Fix NameError: total_images undefined in generate_thumbnails (was defined as
total_media, causing progress logging and response to fail)
- Add URL encoding for paths in scan_output_dir for filenames with spaces
- Exclude thumbnails directory from image monitor to prevent linking thumbnail
files to prompts via fallback mechanism
- Bump version to 3.0.31
The api.queuePrompt wrapper introduced in PR #91 only forwarded 2 of 3
arguments, dropping the options object that carries
partialExecutionTargets. This caused the server to execute all output
nodes instead of just the targeted branch.
Also removes debug console.log and print statements added during
development.
Fixes#94
Fixes#94
The removal of IS_CHANGED in PR #91 caused ComfyUI to always
re-execute the entire graph instead of only changed branches.
IS_CHANGED returns a hash of text inputs (text, prepend_text,
append_text) - when unchanged, ComfyUI skips re-execution.
Add ability to configure a custom image scan directory in Settings:
- New "Image Scan Directory" field in Settings modal
- "Currently Monitoring" display shows active directory path
- Settings API now returns/saves gallery_root_path and monitored_directories
- Image monitor checks GalleryConfig before auto-detecting
- Restart notification when gallery path changes
Closes#76
Change the saveNewPrompt() function to use /prompt_manager/save
instead of /prompt_manager/prompts which has no POST handler.
This was causing a 405 Method Not Allowed error when trying to
add new prompts from the admin interface.
Fixes#89
Resolve conflicts in py/api.py by keeping feature/button's thumbnail
path generation approach (using rel_path.with_suffix('') and string
formatting) which was tested and working correctly.