Commit Graph
6 Commits
Author SHA1 Message Date
Vito Sansevero 113d663fce fix: resolve 15 GitHub code scanning security alerts
- Fix XSS in showFullPrompt() across admin.js, gallery.js, metadata.html
  by replacing HTML string interpolation with DOM manipulation (createElement
  + textContent), eliminating unsafe user content injection
- Fix stack trace exposure in py/api error responses by replacing str(e)
  with generic messages and adding logger.exception() for server-side
  traceability
2026-02-07 13:04:52 -08:00
Vito Sansevero a17ecd02c1 fix: pre-compile Tailwind CSS and track vendor libs (#88)
Replace 398KB Tailwind Play Mode runtime (not for production) with 37KB
pre-compiled CSS. Fix .gitignore so web/lib/ vendor files (Tailwind CSS,
ViewerJS) are tracked — fresh clones were completely broken without them.

- Add gitignore negation rules for web/lib/
- Compile Tailwind v3.4.17 CSS at dev time via standalone CLI
- Replace <script> tags with <link> in admin, gallery, metadata HTML
- Delete tailwind.js runtime (no longer needed)
- Add Makefile with css/css-watch/css-setup targets for devs
- Track ViewerJS vendor files (viewer.min.js, viewer.min.css)
2026-02-07 07:57:31 -08:00
Vito Sansevero 927f1f1df7 build: update Tailwind CSS script source path 2026-02-02 15:10:26 -08:00
Vito Sansevero 638dd44db2 fix(gallery): complete metadata parsing improvements for all gallery views
- Fixed TypeError "text.toLowerCase is not a function" by adding type checking
- Added support for modern ComfyUI node types:
  - CFGGuider for CFG scale values
  - BasicScheduler for steps parameter
  - KSamplerSelect for sampler selection
  - RandomNoise/SeedHistory for seed values
- Unified metadata parsing logic between main gallery and metadata viewer
- Fixed prompt identification to properly distinguish positive vs negative prompts
- Added NaN cleaning for JSON parsing to handle malformed data
- Improved text node analysis with PromptManager priority

All three gallery implementations now correctly parse and display:
- Checkpoint names
- Positive and negative prompts
- Technical parameters (steps, CFG, sampler, seed)
- Support for both legacy and modern ComfyUI workflows

Tested and verified with test_metadata_file.png across all implementations.
2025-08-11 15:30:40 -07:00
Vito Sansevero 6fdfdea89c fix(gallery): enhance metadata parsing for modern ComfyUI workflows
- Add support for new ComfyUI node types in gallery metadata extraction:
  - CFGGuider for CFG scale values
  - BasicScheduler for steps parameter
  - KSamplerSelect for sampler selection
  - RandomNoise/SeedHistory for seed values
- Update both main gallery (/gallery) and metadata viewer (/metadata.html)
- Fix metadata display issues where technical parameters showed as "Unknown"
- Add comprehensive test image and debug tools for validation
- Maintain backward compatibility with legacy KSampler nodes

This resolves metadata parsing issues with modern ComfyUI workflows
that use the newer node architecture for sampling and generation.
2025-08-11 15:15:19 -07:00
Vito Sansevero 6b6ba3c62c feat(prompt_manager): add prepend and append text options 2025-06-03 17:03:18 -07:00