Skip to content

Releases: Einzieg/ComfyUI-custom-api

v0.2.2 — outbound policy and native localization

Choose a tag to compare

@Einzieg Einzieg released this 10 Sep 14:23

Version 0.2.2 addresses the two registration review findings: the outbound request trust boundary and native ComfyUI localization.

Required upgrade step

Outbound requests now require a server-owner-managed network-policy.json in the plugin's private configuration directory. Add only trusted API and image CDN origins, then restart ComfyUI. Existing provider, model and credential data is preserved, but requests remain blocked until their origins are approved. Explicit HTTP proxies are disabled; clear any saved provider proxy.

See the bilingual network policy and migration guide.

Changes

  • Close the SSRF path through editable/imported provider URLs with a deny-by-default, exact-origin allow-list that the UI, API and workflows cannot change.
  • Apply the policy to execution, model discovery, polling, cancellation, image downloads and each redirect. Validate DNS results at connection time and pass the checked IPs directly to the connector. Block metadata/link-local addresses, ambiguous numeric hosts and routing-header overrides.
  • Limit environment-based credentials to separately approved variable names.
  • Use English source strings and ComfyUI's native /i18n resources and Comfy.Locale setting. Chinese remains available without an independent language selector or browser-language override.
  • Preserve image authentication when an equivalent same-origin URL omits the default HTTPS port.

Validation

80 backend tests and 10 frontend tests passed. An isolated ComfyUI 0.35.0 / frontend 1.51.10 instance passed native locale switching, hidden-socket/legacy workflow checks, and text, vision, image generation, image editing and asynchronous workflows against local mock providers.

A controlled reproduction accepted unapproved destinations through both management routes in 0.2.1. In 0.2.2 both return 403 and the unapproved target receives no requests. This release supersedes the earlier scan-only assessment of 0.2.1; publication does not imply Registry security approval.


升级提示:请先按文档配置服务器私有目录中的 network-policy.json 并重启 ComfyUI。界面及导入文件不能修改白名单;已保存的供应商、模型和密钥保留。中文界面现在跟随 ComfyUI 的语言设置。旧版本的 SSRF 问题已修复,Registry 人工审核与 GitHub 发布状态分别追踪。

v0.2.1:修复节点隐藏插槽重叠

Choose a tag to compare

@Einzieg Einzieg released this 09 Sep 13:00

修复新建 API 节点时,隐藏输入插槽叠在“输入图片”附近、仍能被拖出的界面问题。

  • 未启用的输入插槽会被移除;点击“接入节点”才显示,切回“手动输入”后完整移除。
  • 重新打开已有工作流时,清理未启用的残留插槽,并保留已有连线、控件顺序与输入值。
  • 中英文界面均适用。

更新后重启 ComfyUI,再用 Ctrl+F5 强制刷新浏览器页面。已有工作流无需重建。

验证:33 项后端测试、9 项前端测试通过;在真实 ComfyUI 0.35.0 / 前端 1.51.10 中验证鼠标拖动、重复切换输入方式、工作流保存与重载、旧版连线索引和节点复制。

下载 ComfyUI-custom-api-0.2.1.zip 安装;SHA256SUMS.txt 提供校验值。Git / Manager Git 安装可直接更新仓库。

Comfy Registry 版本另需平台审核,上传成功不代表审核通过。若目录暂时无法安装,请使用本页 ZIP 或 Git 安装。

ComfyUI Custom API 0.2.0

Choose a tag to compare

@Einzieg Einzieg released this 09 Sep 11:53

首次公开发布 / First public release

在 ComfyUI 中连接自定义模型 API,支持文本、识图、图像生成和图片编辑。

  • 顶栏供应商管理:名称、图标、Base URL、API Key 与自定义鉴权。
  • 模型自动发现、手动添加、统一搜索和批量操作模板绑定。
  • JSON / 表单 / multipart 请求模板、响应提取及异步轮询。
  • 322 个本地 LobeHub 图标、紧凑节点、中英文界面。
  • 项目图标、重写的中英文 README,以及四张真实 ComfyUI 截图。

安装

下载 ComfyUI-custom-api-0.2.0.zip,将其中的 ComfyUI-custom-api 文件夹放入 ComfyUI/custom_nodes,用 ComfyUI 自己的 Python 安装 requirements.txt,重启并刷新浏览器。SHA256SUMS.txt 提供安装包校验值。

收录状态

Comfy Registry 已可通过官方搜索接口找到,版本 0.2.0 当前等待平台审核。旧版 Manager 的 收录 PR #3258 等待合并。

Registry 的 0.2.0 安装包先于本次 README 和素材更新发布;两者运行时代码相同。此次 GitHub ZIP 包含最新文档和截图。

验证

33 项后端测试、6 项前端测试通过;已在 ComfyUI 0.35.0 / frontend 1.51.10 的 CPU 实例中验证真实工作流。测试及截图均使用演示配置,没有调用收费模型。

MIT licensed. LobeHub assets retain their upstream MIT license. See the English README for setup and usage.