refac(hardening): apply the same safety checks to generated image downloads (#31623)

When an image generation backend returns a link instead of the image itself, the download now goes through the same safety checks used for other external image downloads. Links on the configured ComfyUI address are still trusted as before, so a ComfyUI server on a local network keeps working.
This commit is contained in:
Classic298 2026-09-30 17:08:48 +02:00 • committed by GitHub
parent 6a2aad92f2
commit b4ebd0d62f
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -7,6 +7,7 @@ import logging
import mimetypes
import re
import uuid
from contextlib import nullcontext
from pathlib import Path
from types import SimpleNamespace
from typing import Optional
@ -488,14 +489,18 @@ async def get_image_data(data: str, headers=None, trusted_base_url: str | None =
# that would follow arbitrary redirects.
if trusted_base_url and _is_same_origin(data, trusted_base_url):
log.debug('Skipping URL validation for trusted backend: %s', data)
session_context = nullcontext(await get_session())
else:
await asyncio.to_thread(validate_url, data)
session = await get_session()
async with session.get(
data,
headers=headers,
ssl=AIOHTTP_CLIENT_SESSION_SSL,
) as r:
session_context = get_ssrf_safe_session()
async with (
session_context as session,
session.get(
data,
headers=headers,
ssl=AIOHTTP_CLIENT_SESSION_SSL,
) as r,
):
r.raise_for_status()
content_type = r.headers.get('content-type', '')
if content_type.split('/')[0] == 'image':