Repository navigation
feat(custom-node-list): register bada-ya/ComfyUI-Bada-Utils - #3260
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe custom node registry now includes ComfyUI-Bada-Utils by bada-ya. The entry defines its GitHub repository, ChangesCustom node registry
Suggested reviewers: Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to This adds ComfyUI-Bada-Utils to the custom-node registry with the intended Git repository and clone installation metadata. No current merge-blocking risk is identified. 🚥 Pre-merge checks | ✅ 2✅ Passed checks (2 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Comment |
|
Thanks for the contribution! Two things need addressing before this can be registered:
I'll re-evaluate once these are addressed. |
|
Thank you @ltdrdata for the thorough and helpful review! Both items have been fully addressed in the latest updates:
All Python and JavaScript syntax and unit tests pass cleanly. Please re-evaluate when you have a moment. Thank you again! |
|
Hi @ltdrdata, Just following up with a friendly reminder on this PR! All requested changes (path traversal containment hardening on Whenever you have a chance, please let me know if any further adjustments are needed or if this is ready to be merged. Thank you for your time! |
|
Thanks for the update, and for the thorough work on the file-path side! I re-cloned at HEAD and re-checked. A couple of things landed nicely:
The part that's still open is the built-in terminal API in server/bada_server_api.py. These are open routes with no access control, reachable by any web page the user has open, so a page they visit can drive them from their own machine:
One note in case it comes up: a same-machine / loopback IP check isn't enough here, since a page the user visits makes the request from their own machine — so it would pass that check. The reliable fix is to keep these actions out of network-reachable routes (behind an explicit user action, or removed) and, for the install route, an allow-list of hosts. I'll re-evaluate once these are addressed. |
|
Hi @ltdrdata, Thank you for the detailed and thorough security review! All five flagged endpoints and security risks have been completely removed or refactored in the latest commit (
(Note: The Terminal Hub features have been completely isolated into a separate experimental branch ( The changes have been pushed to |
|
Thanks for the quick and thorough turnaround! I re-cloned at c8f31ff and confirmed it: the terminal exec / open_cmd / install / restart routes and the shell-execution code behind them are all gone, and handing install and restart over to ComfyUI-Manager's own endpoints is the right approach. On the re-check, a few things are left:
Update — one more item from a fuller re-check:
I'll re-evaluate once these are addressed. |
|
Hi @ltdrdata, Thank you for the super fast follow-up review! Both remaining items have been addressed in our latest commit:
The changes have been pushed to |
|
Hi @ltdrdata, Thank you again for the feedback! We have completely removed the Dual Manager launcher feature, its settings option, and its web script (
The branch is updated and clean. Please re-evaluate when convenient. Thanks! |
|
Thanks for the fast turnaround. I re-cloned at One request: some UI text still shows in Korean even when the language setting is English:
Please make these English when you get a chance. For Korean, the locale feature ( |
|
Hi @ltdrdata, Thank you so much for your continuous guidance, patience, and the thorough review process! I really appreciate your time and dedication to making ComfyUI-Manager and custom nodes better and more secure. Following your suggestion, I have updated all remaining hardcoded Korean texts in hub_modal.js, presets_modal.js, missing_node_detective.js, and gemini_api.py to use English defaults. All Korean translations will now be properly served through the standard locale i18n system (bada_i18n.js). Thanks again for all your help! |
Register a new custom node pack: ComfyUI-Bada-Utils
BadaPresetHub,BadaRegionalPrompt,VisualGridPromptNodeDescription
An All-in-One Quality of Life, Smart Presets Hub, Auto Model Assigner & Visual Regional Prompting Suite for ComfyUI.
Key Features
Validation
python json-checker.py custom-node-list.jsonwithout errors..gitsuffix.