Vito Sansevero
be205f3dcc
feat: add pre-commit hooks for local CI checks
...
- Black (auto-fix formatting on commit)
- Flake8 (block on syntax errors and undefined names)
- Bandit (security scan, non-blocking to match CI)
- Tests (run on pre-push only)
- Apply Black formatting fixes caught by the new hooks
2026-02-08 05:27:03 -08:00
Vito Sansevero
ed40be066c
fix: prevent stack trace exposure in SSE error responses
...
Log exception details server-side only; send generic error messages
to clients via SSE streams to resolve code scanning alerts.
2026-02-08 05:23:04 -08:00
Vito
fb092e7c25
Merge pull request #109 from ComfyAssets/fix/security-scanning-issues
...
Fix 15 GitHub code scanning security alerts
2026-02-07 13:08:58 -08:00
Vito Sansevero
55376b4752
fix: remove unused safePrompt variable in admin.js showFullPrompt
...
textContent already treats text as literal, so the escapeHtml() call
was redundant. Removes the unused variable flagged by code quality bot.
2026-02-07 13:07:38 -08:00
Vito Sansevero
113d663fce
fix: resolve 15 GitHub code scanning security alerts
...
- Fix XSS in showFullPrompt() across admin.js, gallery.js, metadata.html
by replacing HTML string interpolation with DOM manipulation (createElement
+ textContent), eliminating unsafe user content injection
- Fix stack trace exposure in py/api error responses by replacing str(e)
with generic messages and adding logger.exception() for server-side
traceability
2026-02-07 13:04:52 -08:00
Vito
85aff0179a
Merge pull request #107 from ComfyAssets/chore/ci-cd-improvements
...
Chore/ci cd improvements
2026-02-07 12:43:49 -08:00
Vito Sansevero
15d5a9197a
style: apply Black formatting to new test files
2026-02-07 12:36:11 -08:00
Vito Sansevero
e1bf06cb3d
test: add comprehensive unit tests for validators, hashing, metadata, config, and prompt tracker
...
Adds 143 new tests across 5 files covering previously untested modules:
- test_validators.py: all 7 validator functions + edge cases
- test_hashing.py: content hash, duplicate detection
- test_metadata_extraction.py: ComfyUI PNG metadata parsing with real images
- test_config.py: GalleryConfig/PromptManagerConfig with mocked PromptServer
- test_prompt_tracker.py: thread-safe prompt tracking, timeouts, context manager
Total test count: 87 → 264
2026-02-07 12:33:48 -08:00
Vito
bbe7a4c217
Update dependabot.yml
...
updating dependabot.
2026-02-07 12:27:32 -08:00
Vito
ccedeba7ec
Create SECURITY.md
...
adding security policy
2026-02-07 12:24:54 -08:00
Vito Sansevero
fde3546574
docs: add CI status badges to README
...
License, Python version, ComfyUI compatibility, Tests, and Code Quality
badges matching KikoTools style.
2026-02-07 12:18:21 -08:00
Vito
7bcc64e0df
Merge pull request #106 from ComfyAssets/dependabot/github_actions/actions/cache-5
...
build(deps): bump actions/cache from 4 to 5
2026-02-07 12:06:59 -08:00
Vito
b799485b74
Merge pull request #105 from ComfyAssets/dependabot/github_actions/actions/setup-python-6
...
build(deps): bump actions/setup-python from 5 to 6
2026-02-07 12:06:38 -08:00
Vito
db1de5eddd
Merge pull request #104 from ComfyAssets/dependabot/github_actions/actions/checkout-6
...
build(deps): bump actions/checkout from 4 to 6
2026-02-07 12:06:09 -08:00
dependabot[bot]
2992b7809d
build(deps): bump actions/cache from 4 to 5
...
Bumps [actions/cache](https://github.com/actions/cache ) from 4 to 5.
- [Release notes](https://github.com/actions/cache/releases )
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md )
- [Commits](https://github.com/actions/cache/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: actions/cache
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-07 16:32:03 +00:00
dependabot[bot]
f7e0c9be2b
build(deps): bump actions/setup-python from 5 to 6
...
Bumps [actions/setup-python](https://github.com/actions/setup-python ) from 5 to 6.
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](https://github.com/actions/setup-python/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: actions/setup-python
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-07 16:32:00 +00:00
dependabot[bot]
5ef0ded757
build(deps): bump actions/checkout from 4 to 6
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4...v6 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-07 16:31:55 +00:00
Vito
4054449650
Merge pull request #103 from ComfyAssets/chore/ci-cd-improvements
...
chore(ci): add code quality, Dependabot, and Black formatting
2026-02-07 08:31:16 -08:00
Vito Sansevero
2737a4b1ef
style: apply Black formatter (line-length=88) to all Python files
...
Automated formatting pass across 30 files to establish consistent code
style enforced by CI. No logic changes.
2026-02-07 08:30:09 -08:00
Vito Sansevero
224fcc7803
chore(ci): add code quality, security scanning, and Dependabot
...
- Add code-quality.yml: Black formatting check, flake8 linting, bandit
security scan
- Add dependabot.yml: weekly updates for pip deps and GitHub Actions
- Add requirements-dev.txt: single source of truth for CI dependencies
- Harden test.yml: add permissions, pip caching, use requirements-dev.txt
- Add Black/flake8/bandit config to pyproject.toml (line-length=88)
2026-02-07 08:30:00 -08:00
Vito Sansevero
5c5fe512c8
chore: bump version to 3.0.33 in pyproject.toml
2026-02-07 08:09:26 -08:00
Vito
a7a79eb75b
Merge pull request #102 from ComfyAssets/fix/phase0-quick-wins
...
fix: pre-compile Tailwind CSS, track vendor libs (#88 )
2026-02-07 08:07:39 -08:00
Vito Sansevero
2a7b53a47b
fix(ci): add missing watchdog dependency to test workflow
...
Tests importing prompt_manager.py fail in CI because watchdog (used by
image_monitor.py) isn't installed. Add it alongside Pillow and aiohttp.
2026-02-07 08:05:01 -08:00
Vito Sansevero
5b67143782
chore: gitignore local/AI tooling files and untrack prompts.db
...
Add .claude/, .serena/, .playwright-mcp/, logs/, docs/, AGENTS.md,
CLAUDE.md, standalone_tagger.py, and prompts.db to .gitignore.
Untrack prompts.db so local database changes don't pollute diffs.
2026-02-07 07:58:51 -08:00
Vito Sansevero
a17ecd02c1
fix: pre-compile Tailwind CSS and track vendor libs ( #88 )
...
Replace 398KB Tailwind Play Mode runtime (not for production) with 37KB
pre-compiled CSS. Fix .gitignore so web/lib/ vendor files (Tailwind CSS,
ViewerJS) are tracked — fresh clones were completely broken without them.
- Add gitignore negation rules for web/lib/
- Compile Tailwind v3.4.17 CSS at dev time via standalone CLI
- Replace <script> tags with <link> in admin, gallery, metadata HTML
- Delete tailwind.js runtime (no longer needed)
- Add Makefile with css/css-watch/css-setup targets for devs
- Track ViewerJS vendor files (viewer.min.js, viewer.min.css)
2026-02-07 07:57:31 -08:00
Vito Sansevero
6271d12426
test: add API integration tests and update CI dependencies
...
Add 26 aiohttp-based API endpoint tests covering health, recent prompts,
search, save/delete, update, tags, categories, stats, export, and
response envelope validation. Add aiohttp to CI workflow dependencies.
2026-02-07 07:35:59 -08:00
Vito Sansevero
45d23efcf1
test: add comprehensive database tests and CI pipeline
...
Phase 6 test infrastructure (6.1, 6.2, 6.5):
- Fix .coveragerc source path (src -> .)
- Fix pre-existing test failure (patch target + method rename)
- Add 52 database layer tests covering CRUD, junction table tags,
search, pagination, statistics, image linking, and edge cases
- Add GitHub Actions CI workflow (Python 3.10-3.12)
- Total: 61 tests, all passing
2026-02-07 07:06:54 -08:00
Vito Sansevero
4deda8542d
feat: normalize tag storage with junction tables
...
Phase 5 scalability and polish:
- Add tags + prompt_tags junction tables replacing JSON column
- Migrate existing JSON tags via json_each() on startup
- Rewrite all tag queries to use junction tables (O(1) vs O(n))
- Simplify rename/delete/merge tag operations to single SQL
- Batch-attach preview images to prompt list responses (fix N+1)
- Fix fetchone() fragility under thread contention (defensive defaults)
2026-02-07 07:02:39 -08:00
Vito Sansevero
4548beb723
refactor: split api.py into domain modules and extract frontend JS
...
Phase 4 structural refactoring:
- Split monolithic py/api.py (5.3k lines) into domain mixins:
prompts.py, images.py, admin.py, logging_routes.py, autotag_routes.py
- Extract inline JS from admin.html into web/js/admin.js
- Extract inline JS from gallery.html into web/js/gallery.js
- Add gzip compression middleware to API responses (Phase 5.4)
- Standardize API error envelope with success: false (Phase 5.3)
- Add filmstrip image enrichment to prompt list responses (Phase 5.2)
2026-02-07 07:02:25 -08:00
Vito Sansevero
4f62066c63
fix: harden nodes, validators, and utility modules
...
Phase 0-3 fixes from codebase audit:
- Extract shared node logic into prompt_manager_base.py (DRY)
- Add input validation guards to validators.py
- Fix logging_config.py buffer management
- Harden image_monitor.py against race conditions
- Fix prompt_tracker.py cleanup edge cases
- Fix diagnostics.py import path
- Wire config.py server instance correctly
2026-02-07 07:02:10 -08:00
Vito
3e3a457fda
Merge pull request #100 from ComfyAssets/feature/tagger
...
Feature/tagger
2026-02-06 14:36:17 -08:00
Vito Sansevero
091689f9f5
chore: bump version to 3.0.32 in pyproject.toml
2026-02-06 14:34:00 -08:00
Vito Sansevero
bd6c136608
refactor(tags-page): improve code structure and reuse
2026-02-06 14:33:26 -08:00
Vito Sansevero
af9ee4e671
feat(web): add load more prompts button
2026-02-06 14:33:10 -08:00
Vito Sansevero
6ef040b4b8
refactor(comfyui): remove class_type conversion logic
2026-02-06 14:32:55 -08:00
Vito Sansevero
a5a1169829
fix(api): handle invalid input and improve progress tracking
2026-02-06 14:32:43 -08:00
Vito Sansevero
9e337ed02a
fix(database): handle skipped prompts in tag operations
2026-02-06 14:32:01 -08:00
Vito
ab5e211019
Merge pull request #98 from ComfyAssets/feature/tag-management-page
...
feat(tags): Phase 2 tag management enhancements
2026-02-03 18:53:10 -08:00
Vito Sansevero
760b2a0f48
feat(tags): add Phase 2 tag management enhancements
...
- Bulk tag operations: rename, delete, merge across all prompts
- Right-click context menu on tags (rename/delete/merge)
- Click prompt card → dashboard search, click thumbnail → ViewerJS
- Usage bars, prompt count badge, staggered card animations
- URL-synced tag selection (#/tags/landscape,portrait?mode=or)
- Untagged prompts filter with [untagged] entry
2026-02-03 18:40:58 -08:00
Vito
778f4670be
Merge pull request #97 from ComfyAssets/fix/gallery-thumbnail-as-posix
...
fix: resolve gallery crash when thumbnails exist
2026-02-03 14:08:22 -08:00
Vito Sansevero
f485825bfb
fix: resolve gallery crash when thumbnails exist and prevent thumbnail-as-image linking
...
- Fix AttributeError: 'str' has no attribute 'as_posix' on thumbnail_rel_path
in get_output_images and find_duplicates (thumbnail_rel_path is already a
string from f-string construction, not a Path object)
- Fix NameError: total_images undefined in generate_thumbnails (was defined as
total_media, causing progress logging and response to fail)
- Add URL encoding for paths in scan_output_dir for filenames with spaces
- Exclude thumbnails directory from image monitor to prevent linking thumbnail
files to prompts via fallback mechanism
- Bump version to 3.0.31
2026-02-03 14:07:23 -08:00
Vito
9e575ab48c
Merge pull request #96 from ComfyAssets/fix/issue-94-branch-execution-v2
...
fix: forward partial execution targets in queuePrompt wrapper
2026-02-03 13:38:01 -08:00
Vito Sansevero
2774ed921b
fix: forward partial execution targets in queuePrompt wrapper
...
The api.queuePrompt wrapper introduced in PR #91 only forwarded 2 of 3
arguments, dropping the options object that carries
partialExecutionTargets. This caused the server to execute all output
nodes instead of just the targeted branch.
Also removes debug console.log and print statements added during
development.
Fixes #94
2026-02-03 13:36:51 -08:00
Vito
4a2cb376da
Merge pull request #95 from ComfyAssets/fix/issue-94-branch-execution
...
fix: restore IS_CHANGED to enable proper branch execution
2026-02-03 08:41:06 -08:00
Vito Sansevero
846b0b64b9
chore: bump version to 3.0.30
2026-02-03 08:39:29 -08:00
Vito Sansevero
557d79c173
fix: restore IS_CHANGED to enable proper branch execution
...
Fixes #94
The removal of IS_CHANGED in PR #91 caused ComfyUI to always
re-execute the entire graph instead of only changed branches.
IS_CHANGED returns a hash of text inputs (text, prepend_text,
append_text) - when unchanged, ComfyUI skips re-execution.
2026-02-03 08:39:22 -08:00
Vito
42aed8e9e3
Merge pull request #93 from ComfyAssets/feature/issue-76-gallery-scan-directory
...
feat(settings): add configurable gallery scan directory
2026-02-02 16:02:04 -08:00
Vito Sansevero
9688e94b4c
chore: bump version to 3.0.29 in pyproject.toml
2026-02-02 16:01:08 -08:00
Vito Sansevero
a7d842a51c
feat(settings): add configurable gallery scan directory
...
Add ability to configure a custom image scan directory in Settings:
- New "Image Scan Directory" field in Settings modal
- "Currently Monitoring" display shows active directory path
- Settings API now returns/saves gallery_root_path and monitored_directories
- Image monitor checks GalleryConfig before auto-detecting
- Restart notification when gallery path changes
Closes #76
2026-02-02 15:58:54 -08:00
Vito Sansevero
4f273e9b21
chore: bump version to 3.0.28 in pyproject.toml
2026-02-02 15:21:58 -08:00