fix: audit hardening — input validation, error handling, and robustness (#25)
* fix: audit hardening — input validation, error handling, and robustness - immich_api: guard person["id"] with .get() + early return on missing field - immich_api: include page number in pagination exception log - immich_api: validate faces response is a list before indexing - executor: wrap Image.open() in try/except for non-image HTTP responses - executor: strip leading 'v' from Frigate version before parsing (v0.16.0 was misread) - config: wrap FRIGATE_SCORE_CEILING float() parse in try/except with warning - config: warn when both DATA_DIR and legacy CWD config files exist simultaneously - scheduler: wrap PID file write in try/except so /tmp failures don't crash startup - scheduler: clamp sleep to 60s max to bound recovery time after NTP clock jumps - frigate_api: log unexpected non-list type in get_frigate_person_files at DEBUG * fix: LIMIT env var crash and symlink guard on person output dir - jobs: wrap int(LIMIT) parse in try/except — bad value (e.g. "30.5", "all") now logs a warning and falls back to the default instead of crashing - executor: check for symlink before shutil.rmtree on person_dir — prevents following a symlink out of OUTPUT_DIR on a shared volume * chore: bump version to 0.5.3
This commit is contained in:
+15
-1
@@ -93,7 +93,14 @@ class _Config:
|
||||
self.MAX_AUTO_IMAGES = int(os.getenv("MAX_AUTO_IMAGES", "20"))
|
||||
self.QUALITY_REPLACEMENT = os.getenv("QUALITY_REPLACEMENT", "true").lower() in ("true", "1", "yes")
|
||||
_ceiling_env = os.getenv("FRIGATE_SCORE_CEILING", "").strip()
|
||||
self.FRIGATE_SCORE_CEILING = float(_ceiling_env) if _ceiling_env else None
|
||||
if _ceiling_env:
|
||||
try:
|
||||
self.FRIGATE_SCORE_CEILING = float(_ceiling_env)
|
||||
except ValueError:
|
||||
logging.warning("FRIGATE_SCORE_CEILING=%r is not a valid float — ignoring", _ceiling_env)
|
||||
self.FRIGATE_SCORE_CEILING = None
|
||||
else:
|
||||
self.FRIGATE_SCORE_CEILING = None
|
||||
self.ENABLE_FRIGATE_SCORES = os.getenv("ENABLE_FRIGATE_SCORES", "true").lower() in ("true", "1", "yes")
|
||||
self.FACE_MARGIN = float(os.getenv("FACE_MARGIN", "0.15"))
|
||||
self.USE_FULL_RESOLUTION = os.getenv("USE_FULL_RESOLUTION", "true").lower() in ("true", "1", "yes")
|
||||
@@ -116,6 +123,13 @@ class _Config:
|
||||
# Prefer DATA_DIR/.immich_config.json (volume-safe in Docker) and fall back
|
||||
# to the legacy CWD path so existing installations continue to work.
|
||||
_data_cfg = Path(self.DATA_DIR) / ".immich_config.json"
|
||||
if _data_cfg.exists() and _LEGACY_CONFIG_FILE.exists():
|
||||
logging.warning(
|
||||
"Two config files found: %s and %s — using %s. Remove the legacy file to silence this.",
|
||||
_data_cfg,
|
||||
_LEGACY_CONFIG_FILE,
|
||||
_data_cfg,
|
||||
)
|
||||
config_file = _data_cfg if _data_cfg.exists() else _LEGACY_CONFIG_FILE
|
||||
if config_file.exists():
|
||||
try:
|
||||
|
||||
Reference in New Issue
Block a user