Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Blocked Paths Fix #10304

Merged
merged 5 commits into from
Jan 8, 2025
Merged

Blocked Paths Fix #10304

merged 5 commits into from
Jan 8, 2025

Conversation

freddyaboulton
Copy link
Collaborator

Description

Please include a concise summary, in clear English, of the changes in this pull request. If it closes an issue, please mention it here.

🎯 PRs Should Target Issues

Before your create a PR, please check to see if there is an existing issue for this change. If not, please create an issue before you create this PR, unless the fix is very small.

Not adhering to this guideline will result in the PR being closed.

Testing and Formatting Your Code

  1. PRs will only be merged if tests pass on CI. We recommend at least running the backend tests locally, please set up your Gradio environment locally and run the backed tests: bash scripts/run_backend_tests.sh

  2. Please run these bash scripts to automatically format your code: bash scripts/format_backend.sh, and (if you made any changes to non-Python files) bash scripts/format_frontend.sh

@gradio-pr-bot
Copy link
Collaborator

gradio-pr-bot commented Jan 7, 2025

🪼 branch checks and previews

Name Status URL
Spaces ready! Spaces preview
Website ready! Website preview
🦄 Changes detected! Details

Install Gradio from this PR

pip install https://gradio-pypi-previews.s3.amazonaws.com/a8544007efc07ccbc89bbf85cee9044272d1a309/gradio-5.10.0-py3-none-any.whl

Install Gradio Python Client from this PR

pip install "gradio-client @ git+https://github.com/gradio-app/gradio@a8544007efc07ccbc89bbf85cee9044272d1a309#subdirectory=client/python"

Install Gradio JS Client from this PR

npm install https://gradio-npm-previews.s3.amazonaws.com/a8544007efc07ccbc89bbf85cee9044272d1a309/gradio-client-1.9.0.tgz

Use Lite from this PR

<script type="module" src="https://gradio-lite-previews.s3.amazonaws.com/a8544007efc07ccbc89bbf85cee9044272d1a309/dist/lite.js""></script>

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
@gradio-pr-bot
Copy link
Collaborator

gradio-pr-bot commented Jan 7, 2025

🦄 change detected

This Pull Request includes changes to the following packages.

Package Version
gradio minor
  • Maintainers can select this checkbox to manually select packages to update.

With the following changelog entry.

Blocked Paths Fix

Maintainers or the PR author can modify the PR title to modify this entry.

Something isn't right?

  • Maintainers can change the version label to modify the version bump.
  • If the bot has failed to detect any changes, or if this pull request needs to update multiple packages to different versions or requires a more comprehensive changelog entry, maintainers can update the changelog file directly.

Sorry, something went wrong.

@freddyaboulton freddyaboulton marked this pull request as ready for review January 7, 2025 20:26
Copy link
Member

@abidlabs abidlabs left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The code changes look right but for some reason, I'm seeing some unexpected behavior when I test this PR.

(1) On one hand, the test pytest test/test_routes.py::TestRoutes::test_blocked_path_case_insensitive passes for me even without these changes. I'm testing on MacOS which should be case-insensitive

(2) On the other hand, when I try the repro from the GHSA-j2jg-fq62-7c3h, I can still access files I should not able to access, e.g.

http://127.0.0.1:7862/gradio_api/file=resources/ADMIN/credentials.txt

Let me know @freddyaboulton @dawoodkhan82 if you are not seeing this and I can did deeper to see if its an issue in my local environment.

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
@freddyaboulton
Copy link
Collaborator Author

@abidlabs - I modified the test so that it fails on main and passes in the PR. Good catch. The external repro always failed for me in this PR though.

@abidlabs
Copy link
Member

abidlabs commented Jan 8, 2025

LGTM thanks @freddyaboulton for updating the test! I figured out the issue was that I wasn't providing absolute paths for blocked_paths and allowed_paths (as per the repro). With absolute paths, the behavior is as expected!

@freddyaboulton freddyaboulton enabled auto-merge (squash) January 8, 2025 19:23
@freddyaboulton freddyaboulton merged commit 6b63fde into main Jan 8, 2025
22 checks passed
@freddyaboulton freddyaboulton deleted the blocked-paths-fix branch January 8, 2025 19:29
dawoodkhan82 pushed a commit that referenced this pull request Jan 13, 2025
* add code

* add changeset

* Fix test

* empty

---------

Co-authored-by: gradio-pr-bot <gradio-pr-bot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants