mirror of
https://github.com/saphid/frame-control.git
synced 2026-10-06 03:00:18 +02:00
Fix the final review's findings on the combined features
- Links to localhost need FRAME_CONTROL_LOCAL_LINKS=1: otherwise any website's link could make the app fetch from services on this computer. - Title staging folders (unzipped titles) carry the server's PID and are swept on the next start like download folders, so quitting mid-install doesn't leave gigabytes behind. - An install from a link refreshes Sideloaded titles. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
636a4a47b7
commit
2ab2ffa65a
6 files changed
+65
-41
No files matched your search
+4
-3
@@ -39,6 +39,7 @@ DIR_RE = re.compile(r'^/[A-Za-z0-9_./-]+$')
|
||||
# Zip limits: well above any real game, well below a zip bomb.
|
||||
MAX_UNPACKED = 64 * 1024**3
|
||||
MAX_ENTRIES = 200000
|
||||
TMP_PREFIX = 'frame-title-' # then the server's PID, so server.sweep_tmp can clear a killed run's
|
||||
MAX_RATIO = 200 # uncompressed / compressed, once past 1 GB
|
||||
|
||||
# The Steam compat tool aliases Valve's client uses (devkit_client RUNTIME_ALIASES).
|
||||
@@ -423,15 +424,15 @@ def inspect(path, name=None):
|
||||
if _has_links(root):
|
||||
# scp -r follows links, so a link out of the folder could upload
|
||||
# anything; copy the folder with its links made safe first.
|
||||
work = tempfile.mkdtemp(prefix='frame-title-')
|
||||
work = tempfile.mkdtemp(prefix=f'{TMP_PREFIX}{os.getpid()}-')
|
||||
root = _stage_folder(root, os.path.join(work, os.path.basename(root)))
|
||||
elif path.lower().endswith('.zip'):
|
||||
work = tempfile.mkdtemp(prefix='frame-title-')
|
||||
work = tempfile.mkdtemp(prefix=f'{TMP_PREFIX}{os.getpid()}-')
|
||||
extract_zip(path, work)
|
||||
root = _unwrap(work)
|
||||
elif classify(path):
|
||||
# A single executable is uploaded on its own; don't copy a whole Downloads folder.
|
||||
work = tempfile.mkdtemp(prefix='frame-title-')
|
||||
work = tempfile.mkdtemp(prefix=f'{TMP_PREFIX}{os.getpid()}-')
|
||||
shutil.copy2(path, os.path.join(work, os.path.basename(path)))
|
||||
root = work
|
||||
else:
|
||||
|
||||
Reference in new issue
Block a user