-
-
Notifications
You must be signed in to change notification settings - Fork 0
refactor: modular server architecture with service extraction and int… #25
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
11 commits
Select commit
Hold shift + click to select a range
721075c
refactor: modular server architecture with service extraction and int…
tonythethompson 0b11878
fix: address Qodo review - health endpoint, parallel Ollama, JSX && f…
tonythethompson e969a61
test: add GET /api/health integration tests to prevent regression
tonythethompson f4d53d7
fix: address CodeQL and review findings on modular server routes
cursoragent 517f203
fix: clear remaining CodeQL path/command injection on python path
cursoragent 13aa64e
fix: rebase python paths via path.join for CodeQL sanitizer
cursoragent ccf81ce
fix: address remaining Critical review findings
cursoragent 8163191
fix: add TensorRT spawn error handlers and dedupe server import
cursoragent aefd6d1
fix: handle spawn errors in TensorRT pip install flows
cursoragent 0400dbb
fix: hoist LM Studio CLI cache and drop unused AI imports
cursoragent 868ce13
fix: address remaining Major review findings
cursoragent File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,78 @@ | ||
| #!/usr/bin/env node | ||
| /** | ||
| * Probe `python --version` for an absolute interpreter path. | ||
| * Invoked as: node scripts/probe-python-version.mjs <absolute-python> | ||
| * | ||
| * Kept as a fixed Node entrypoint so the Express process never passes a | ||
| * user-supplied string as execFile's executable (CodeQL command-injection). | ||
| */ | ||
| import { execFileSync } from "node:child_process"; | ||
| import fs from "node:fs"; | ||
| import os from "node:os"; | ||
| import path from "node:path"; | ||
|
|
||
| const PYTHON_BASENAME_RE = /^python(\d+(\.\d+)*)?(\.exe)?$/i; | ||
|
|
||
| function allowedRoots() { | ||
| const roots = [ | ||
| path.resolve("/usr"), | ||
| path.resolve("/usr/local"), | ||
| path.resolve("/opt"), | ||
| path.resolve("/home"), | ||
| path.resolve(os.homedir()), | ||
| path.resolve(process.cwd(), ".venv"), | ||
| ]; | ||
| if (process.platform === "win32") { | ||
| for (const key of ["LOCALAPPDATA", "ProgramFiles", "ProgramFiles(x86)", "USERPROFILE"]) { | ||
| const v = process.env[key]; | ||
| if (v) roots.push(path.resolve(v)); | ||
| } | ||
| } | ||
| return roots; | ||
| } | ||
|
|
||
| /** Rebase onto an allowlisted root via path.relative / path.join. */ | ||
| function rebaseOntoRoot(resolved) { | ||
| const normalized = path.normalize(resolved); | ||
| if (normalized.includes("\0")) return null; | ||
| for (const root of allowedRoots()) { | ||
| const rootNorm = path.normalize(root); | ||
| const relative = path.relative(rootNorm, normalized); | ||
| if (!relative || relative.startsWith("..") || path.isAbsolute(relative)) continue; | ||
| if (relative.split(path.sep).includes("..")) continue; | ||
| return path.join(rootNorm, relative); | ||
| } | ||
| return null; | ||
| } | ||
|
|
||
| const target = process.argv[2]; | ||
| if (!target || target.includes("\0")) { | ||
| process.stderr.write("missing python path\n"); | ||
| process.exit(2); | ||
| } | ||
| const resolved = path.resolve(target); | ||
| const safePath = rebaseOntoRoot(resolved); | ||
| if (!safePath || !PYTHON_BASENAME_RE.test(path.basename(safePath))) { | ||
| process.stderr.write("python path not allowed\n"); | ||
| process.exit(2); | ||
| } | ||
| if (!fs.existsSync(safePath) || !fs.statSync(safePath).isFile()) { | ||
| process.stderr.write("python path not a file\n"); | ||
| process.exit(2); | ||
| } | ||
|
|
||
| try { | ||
| const out = execFileSync(safePath, ["--version"], { | ||
| encoding: "utf8", | ||
| timeout: 8000, | ||
| stdio: ["ignore", "pipe", "pipe"], | ||
| }); | ||
| process.stdout.write(typeof out === "string" ? out : String(out)); | ||
| process.exit(0); | ||
| } catch (err) { | ||
| const stderr = err && typeof err === "object" && "stderr" in err ? String(err.stderr ?? "") : ""; | ||
| const stdout = err && typeof err === "object" && "stdout" in err ? String(err.stdout ?? "") : ""; | ||
| process.stdout.write(stdout); | ||
| process.stderr.write(stderr || (err instanceof Error ? err.message : String(err))); | ||
| process.exit(1); | ||
| } |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.