From 08a8062a01529afc4ee8ced4382e7f8cd7a34bc9 Mon Sep 17 00:00:00 2001 From: HYC Fixer Date: Sun, 30 Aug 2026 12:26:30 +0800 Subject: [PATCH] =?UTF-8?q?fix:=20check=5Fauth=20=E5=89=8D=E7=BC=80?= =?UTF-8?q?=E5=8C=B9=E9=85=8D=E5=8E=BB=E5=B0=BE=E6=96=9C=E6=9D=A0=E9=81=BF?= =?UTF-8?q?=E5=85=8D=E5=8F=8C=E6=96=9C=E6=9D=A0=E4=B8=8D=E5=91=BD=E4=B8=AD?= =?UTF-8?q?(=E5=85=AC=E5=BC=80/=E5=8F=97=E4=BF=9D=E6=8A=A4=E7=AB=AF?= =?UTF-8?q?=E7=82=B9=E5=88=A4=E5=AE=9A=E4=BF=AE=E6=AD=A3)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- handlers/http_handler.py | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/handlers/http_handler.py b/handlers/http_handler.py index 798aa17..e185625 100644 --- a/handlers/http_handler.py +++ b/handlers/http_handler.py @@ -343,17 +343,20 @@ class MirrorServerHandler(BaseHTTPRequestHandler): # 任何方法都公开 for endpoint in public_any: - if check_path == endpoint or check_path.startswith(endpoint + '/'): + ep = endpoint.rstrip('/') + if check_path == ep or check_path.startswith(ep + '/'): return True if method in ('GET', 'HEAD'): - # 只读公开端点放行 + # 只读公开端点放行(去尾斜杠后按前缀匹配,避免双斜杠不命中) for endpoint in public_get: - if check_path == endpoint or check_path.startswith(endpoint + '/'): + ep = endpoint.rstrip('/') + if check_path == ep or check_path.startswith(ep + '/'): return True # 其余 GET: 命中受保护前缀才需要认证 for endpoint in protected_endpoints: - if check_path.startswith(endpoint): + ep = endpoint.rstrip('/') + if check_path == ep or check_path.startswith(ep + '/'): return self._do_auth(auth_type) return True