-
Notifications
You must be signed in to change notification settings - Fork 2.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Blocked Paths Fix #10304
Blocked Paths Fix #10304
Conversation
🪼 branch checks and previews
Install Gradio from this PR pip install https://gradio-pypi-previews.s3.amazonaws.com/a8544007efc07ccbc89bbf85cee9044272d1a309/gradio-5.10.0-py3-none-any.whl Install Gradio Python Client from this PR pip install "gradio-client @ git+https://github.com/gradio-app/gradio@a8544007efc07ccbc89bbf85cee9044272d1a309#subdirectory=client/python" Install Gradio JS Client from this PR npm install https://gradio-npm-previews.s3.amazonaws.com/a8544007efc07ccbc89bbf85cee9044272d1a309/gradio-client-1.9.0.tgz Use Lite from this PR <script type="module" src="https://gradio-lite-previews.s3.amazonaws.com/a8544007efc07ccbc89bbf85cee9044272d1a309/dist/lite.js""></script> |
🦄 change detectedThis Pull Request includes changes to the following packages.
With the following changelog entry.
Maintainers or the PR author can modify the PR title to modify this entry.
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The code changes look right but for some reason, I'm seeing some unexpected behavior when I test this PR.
(1) On one hand, the test pytest test/test_routes.py::TestRoutes::test_blocked_path_case_insensitive
passes for me even without these changes. I'm testing on MacOS which should be case-insensitive
(2) On the other hand, when I try the repro from the GHSA-j2jg-fq62-7c3h, I can still access files I should not able to access, e.g.
http://127.0.0.1:7862/gradio_api/file=resources/ADMIN/credentials.txt
Let me know @freddyaboulton @dawoodkhan82 if you are not seeing this and I can did deeper to see if its an issue in my local environment.
@abidlabs - I modified the test so that it fails on main and passes in the PR. Good catch. The external repro always failed for me in this PR though. |
LGTM thanks @freddyaboulton for updating the test! I figured out the issue was that I wasn't providing absolute paths for |
* add code * add changeset * Fix test * empty --------- Co-authored-by: gradio-pr-bot <gradio-pr-bot@users.noreply.github.com>
Description
Please include a concise summary, in clear English, of the changes in this pull request. If it closes an issue, please mention it here.
🎯 PRs Should Target Issues
Before your create a PR, please check to see if there is an existing issue for this change. If not, please create an issue before you create this PR, unless the fix is very small.
Not adhering to this guideline will result in the PR being closed.
Testing and Formatting Your Code
PRs will only be merged if tests pass on CI. We recommend at least running the backend tests locally, please set up your Gradio environment locally and run the backed tests:
bash scripts/run_backend_tests.sh
Please run these bash scripts to automatically format your code:
bash scripts/format_backend.sh
, and (if you made any changes to non-Python files)bash scripts/format_frontend.sh