Skip to content
GitLab
Menu
Projects
Groups
Snippets
Loading...
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
Menu
Open sidebar
chenpangpang
open-webui
Commits
554e5668
Unverified
Commit
554e5668
authored
Apr 01, 2024
by
Timothy Jaeryang Baek
Committed by
GitHub
Apr 01, 2024
Browse files
Merge pull request from GHSA-39wr-r5vm-3jxj
fix: allowed hosts
parents
edeff20e
77b1edcd
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
7 additions
and
0 deletions
+7
-0
backend/apps/ollama/main.py
backend/apps/ollama/main.py
+7
-0
No files found.
backend/apps/ollama/main.py
View file @
554e5668
...
@@ -970,6 +970,13 @@ def parse_huggingface_url(hf_url):
...
@@ -970,6 +970,13 @@ def parse_huggingface_url(hf_url):
async
def
download_file_stream
(
async
def
download_file_stream
(
ollama_url
,
file_url
,
file_path
,
file_name
,
chunk_size
=
1024
*
1024
ollama_url
,
file_url
,
file_path
,
file_name
,
chunk_size
=
1024
*
1024
):
):
allowed_hosts
=
[
"https://huggingface.co/"
,
"https://github.com/"
]
if
not
any
(
file_url
.
startswith
(
host
)
for
host
in
allowed_hosts
):
raise
ValueError
(
"Invalid file_url. Only URLs from allowed hosts are permitted."
)
done
=
False
done
=
False
if
os
.
path
.
exists
(
file_path
):
if
os
.
path
.
exists
(
file_path
):
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment