Pull requests / #1044

#1044 serve: image sources - network paths refused, URLs capped and fetched outside the FIFO, no local files for other origins' pages

closed · @sergqwer · 0 comentários · No GitHub

Server & APIWindows

Descrição

Replaces #553. GitHub closed it on 2026-10-05, when my fork was made private by mistake: that took the fork out of the network for good, so it can no longer open pull requests. This is the same branch and commit (`04a0cd2`), opened from a new fork; the discussion and the measurements are in #553.

---

`Vision.load()` takes any image source a request names:
- a `data:` URL;
- any `http(s)` URL, read whole with no size cap, under the global request FIFO;
- `file://...`;
- any path `os.path.isfile` accepts.

Three problems, all in `serve/server.py`:

1. **Network paths.** A UNC path (`\host\share\x.png`, `//host/share/...`, `\?\UNC\...`, `file://host/share/...`) makes Windows open an SMB connection to that host and sign in with the user's NTLM credentials, at the first `os.path.isfile`. These are now refused before anything looks at the path. `file://host/...` was also read as a relative path before.
2. **URL size and the FIFO.**
   - A URL is read up to 32 MiB (`IMAGE_URL_MAX`), and a larger `Content-Length` is refused unread.
   - A URL that cannot be read is a 400 that says so, not a dropped connection.
   - The download happens before the FIFO is taken: under it, a slow image server held every other request for up to 60 s.
3. **Pages of another origin.** With no `api_key` (the default), `/v1/messages` and `/v1/chat/completions` read the body as JSON whatever its Content-Type. So any web page the user opens can send a `text/plain` POST, a simple request with no CORS preflight, and have the server read a local file as an image. The page gets no answer to read unless `cors_origins` allows it, but the file is read, and a UNC path leaks the hash.
   - A request whose `Origin` is not the server's own (nor in `trusted_origins`) may now send only `data:` and `http(s)` images. That is `_foreign_origin()`, factored out of `_own_page()`.
   - Clients that send no `Origin` (CLI tools, SDKs, agents) and Strata's own page work as before.

Tests (`ImageSources`): each network form is refused without `isfile` being called; the cap, with and without `Content-Length`, and a 404; the download runs with the FIFO free; a foreign-origin request is refused on both APIs while the allowed forms pass. Serve tests: 176 OK (7 skipped).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01VZy1yKaDDiA8a7svdwaHio

No site

Links install, modelos, releases.