mirror of
https://github.com/vladmandic/automatic
synced 2026-09-20 01:31:13 +02:00
fix(api): IP-adapter mask accumulation, null params, colon-in-password, raw allowed path
generate.py: p.ip_adapter_masks was reinitialized inside the per-adapter loop, discarding all but the last adapter's masks; move it beside the other accumulators. process.py: req.params is dict|None, so a null params body crashed .items() in post_preprocess/post_mask. api.py: split(':') without maxsplit broke auth/auth-file entries whose password contains a colon. gallery.py: allowed_paths stored quote(path) but the membership check and path guards use the raw path, causing duplicate accumulation and an ineffective whitelist; also drop the unused FastAPI import (pylint W0611 surfaced when this file is linted).
Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -3,7 +3,6 @@ import os
|
||||
import time
|
||||
import base64
|
||||
from urllib.parse import quote, unquote
|
||||
from fastapi import FastAPI
|
||||
from fastapi.responses import JSONResponse
|
||||
from starlette.websockets import WebSocket, WebSocketState
|
||||
from pydantic import BaseModel, Field # pylint: disable=no-name-in-module
|
||||
@@ -173,7 +172,7 @@ def register_api(api): # register api
|
||||
unique_folders.append(f)
|
||||
if shared.demo is not None and path not in shared.demo.allowed_paths:
|
||||
debug(f'Browser folders allow: {path}')
|
||||
shared.demo.allowed_paths.append(quote(path))
|
||||
shared.demo.allowed_paths.append(path)
|
||||
debug(f'Browser folders: {unique_folders}')
|
||||
return JSONResponse(content=unique_folders)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user