P2: 清理与一致性
- CLI: --preset 实际生效;--directory-listing/--enable-stats/--enable-*/--ignore-hidden 支持 true/false(修复 type=bool 陷阱),未显式传入时不再覆盖 settings.json - 版本号统一 v2.3(settings.json/config.py/v1/v2/Dockerfile) - 移除硬编码 /tmp/pypi_debug.log 写文件;v2 裸 except 改记录错误返回 500 - webhook id 非法输入返回 400;下载趋势 timedelta 导入提升修复 NameError - 打包模式 auth_token 写入 exe 目录(不再写入 _MEIPASS) - README 修正: 线程池架构、pyinstaller 构建方式 - mirrors/__init__.py ' Quay.io' 笔误;chunked 响应去掉 Content-Length;docs/ui realpath 边界 - SQLite WAL+busy_timeout;下载计数原子 UPDATE - requirements 移除未使用的 cachetools/apscheduler
This commit is contained in:
@@ -668,7 +668,7 @@ class MirrorServerHandler(BaseHTTPRequestHandler):
|
||||
file_path = os.path.join(docs_dir, rel_path)
|
||||
|
||||
# 防止目录遍历
|
||||
if not os.path.realpath(file_path).startswith(os.path.realpath(docs_dir)):
|
||||
if not os.path.realpath(file_path).startswith(os.path.realpath(docs_dir) + os.sep):
|
||||
self.send_error(403, "Access denied")
|
||||
return
|
||||
|
||||
@@ -765,7 +765,7 @@ class MirrorServerHandler(BaseHTTPRequestHandler):
|
||||
file_path = os.path.join(ui_dir, rel_path)
|
||||
|
||||
# 防止目录遍历
|
||||
if not os.path.realpath(file_path).startswith(os.path.realpath(ui_dir)):
|
||||
if not os.path.realpath(file_path).startswith(os.path.realpath(ui_dir) + os.sep):
|
||||
self.send_error(403, "Access denied")
|
||||
return
|
||||
|
||||
@@ -1200,7 +1200,7 @@ class MirrorServerHandler(BaseHTTPRequestHandler):
|
||||
mime_type, _ = mimetypes.guess_type(file_path)
|
||||
self.send_response(200)
|
||||
self.send_header("Content-Type", mime_type)
|
||||
self.send_header("Content-Length", str(file_size))
|
||||
# 使用 chunked 时不发送 Content-Length(协议不允许同时存在)
|
||||
self.send_header("Content-Disposition",
|
||||
f'attachment; filename="{self._safe_disposition_filename(file_path)}"')
|
||||
self.send_header("Accept-Ranges", "bytes")
|
||||
|
||||
Reference in New Issue
Block a user