mirror of
https://github.com/open-webui/open-webui.git
synced 2026-10-05 02:41:34 +00:00
refac(hardening): apply the same safety checks to generated image downloads (#31623)
When an image generation backend returns a link instead of the image itself, the download now goes through the same safety checks used for other external image downloads. Links on the configured ComfyUI address are still trusted as before, so a ComfyUI server on a local network keeps working.
This commit is contained in:
parent
6a2aad92f2
commit
b4ebd0d62f
1 changed files with 11 additions and 6 deletions
|
|
@ -7,6 +7,7 @@ import logging
|
|||
import mimetypes
|
||||
import re
|
||||
import uuid
|
||||
from contextlib import nullcontext
|
||||
from pathlib import Path
|
||||
from types import SimpleNamespace
|
||||
from typing import Optional
|
||||
|
|
@ -488,14 +489,18 @@ async def get_image_data(data: str, headers=None, trusted_base_url: str | None =
|
|||
# that would follow arbitrary redirects.
|
||||
if trusted_base_url and _is_same_origin(data, trusted_base_url):
|
||||
log.debug('Skipping URL validation for trusted backend: %s', data)
|
||||
session_context = nullcontext(await get_session())
|
||||
else:
|
||||
await asyncio.to_thread(validate_url, data)
|
||||
session = await get_session()
|
||||
async with session.get(
|
||||
data,
|
||||
headers=headers,
|
||||
ssl=AIOHTTP_CLIENT_SESSION_SSL,
|
||||
) as r:
|
||||
session_context = get_ssrf_safe_session()
|
||||
async with (
|
||||
session_context as session,
|
||||
session.get(
|
||||
data,
|
||||
headers=headers,
|
||||
ssl=AIOHTTP_CLIENT_SESSION_SSL,
|
||||
) as r,
|
||||
):
|
||||
r.raise_for_status()
|
||||
content_type = r.headers.get('content-type', '')
|
||||
if content_type.split('/')[0] == 'image':
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue