multimodalart HF Staff commited on
Commit
898e68e
·
verified ·
1 Parent(s): 032f95e

Update app.py

Browse files
Files changed (1) hide show
  1. app.py +31 -50
app.py CHANGED
@@ -1,71 +1,52 @@
1
  import gradio as gr
 
2
 
3
- # Problematic URL that triggers the SSRF validation error
4
- # This is a legitimate Hugging Face URL that should be allowed
5
- problematic_url = "https://huggingface.co/Norod78/Flux_1_Dev_LoRA_Paper-Cutout-Style/resolve/main/08a19840b6214b76b0607b2f9d5a7e28_63159b9d98124c008efb1d36446a615c.png"
6
-
7
- # Sample data with image URLs (similar to loras_state)
8
- sample_data = [
9
  {
10
- "title": "Sample LoRA",
11
- "image": problematic_url, # This URL causes the issue
12
- "repo": "some/repo"
 
13
  }
14
  ]
15
 
16
- def add_item_function(text_input, state_data):
17
- """
18
- This function should be called when button is clicked,
19
- but the error occurs before it even executes when gallery is in outputs.
20
- """
21
- print("Function was called!") # This should appear in logs but doesn't
22
-
23
- # Add a new item to state
24
- new_item = {
25
- "title": f"New Item: {text_input}",
26
- "image": problematic_url, # This URL in the return value triggers SSRF
27
- "repo": "new/repo"
28
- }
29
- state_data.append(new_item)
30
 
31
- # Format data for gallery: list of (image, title) tuples
32
- gallery_data = [(item["image"], item["title"]) for item in state_data]
33
 
34
- # Use gr.update() to match the original code pattern exactly
35
- return f"Added: {text_input}", state_data, gr.update(value=gallery_data)
 
 
36
 
37
- # Create the interface
38
  with gr.Blocks() as demo:
39
- gr.Markdown("# Gradio SSRF Bug Reproduction")
40
- gr.Markdown("Click the button below. You should see an error about hostname validation.")
41
- gr.Markdown("The error occurs when the function tries to return data that will update a gallery with HuggingFace URLs.")
42
-
43
- # State containing URLs that trigger the issue
44
- state_var = gr.State(sample_data)
45
 
46
- # Simple text input
47
- text_input = gr.Textbox(label="Enter some text", value="test")
48
 
49
- # Gallery that will be updated with the problematic URLs
 
50
  gallery = gr.Gallery(
51
- label="Gallery",
52
- value=[(item["image"], item["title"]) for item in sample_data],
53
- columns=3
54
  )
55
 
56
- # Output textbox
57
- output = gr.Textbox(label="Output")
58
 
59
- # Button that triggers the error
60
- button = gr.Button("Add item - this will fail")
61
 
62
- # This fails with: ValueError: Hostname cas-bridge-direct.xethub.hf.co failed validation
63
- # The error occurs when Gradio tries to process the gallery update with the HF URLs
64
- button.click(
65
- fn=add_item_function,
66
- inputs=[text_input, state_var],
67
- outputs=[output, state_var, gallery] # Including gallery in outputs triggers the error
68
  )
69
 
70
  if __name__ == "__main__":
 
 
71
  demo.launch()
 
1
  import gradio as gr
2
+ import json
3
 
4
+ # Sample data with HuggingFace image URLs that redirect to cas-bridge-direct.xethub.hf.co
5
+ sample_loras = [
 
 
 
 
6
  {
7
+ "image": "https://huggingface.co/Norod78/Flux_1_Dev_LoRA_Paper-Cutout-Style/resolve/main/08a19840b6214b76b0607b2f9d5a7e28_63159b9d98124c008efb1d36446a615c.png",
8
+ "title": "Paper Cutout",
9
+ "repo": "Norod78/Flux_1_Dev_LoRA_Paper-Cutout-Style",
10
+ "trigger_word": ", Paper Cutout Style"
11
  }
12
  ]
13
 
14
+ def add_custom_lora_broken(custom_lora, selected_indices, current_loras, gallery):
15
+ """This version breaks because it passes current_loras (containing HF URLs) as function input"""
16
+ print("Starting to load a custom LoRA...") # This won't print due to preprocessing error
 
 
 
 
 
 
 
 
 
 
 
17
 
18
+ if custom_lora:
19
+ pass
20
 
21
+ return current_loras, gr.update(), gr.update(), gr.update(), selected_indices
22
+
23
+ # Initialize state with URLs that will cause SSRF validation issues
24
+ loras_state = gr.State(sample_loras)
25
 
 
26
  with gr.Blocks() as demo:
27
+ gr.Markdown("# SSRF Validation Bug Reproduction")
 
 
 
 
 
28
 
29
+ selected_indices = gr.State([])
 
30
 
31
+ custom_lora_input = gr.Textbox(label="Custom LoRA", placeholder="Enter custom LoRA")
32
+
33
  gallery = gr.Gallery(
34
+ [(item["image"], item["title"]) for item in sample_loras],
35
+ label="LoRA Gallery",
36
+ columns=2
37
  )
38
 
39
+ broken_button = gr.Button("Add Custom LoRA (Broken - passes state with URLs)")
 
40
 
41
+ error_display = gr.Textbox(label="Error/Success", interactive=False)
 
42
 
43
+ broken_button.click(
44
+ add_custom_lora_broken,
45
+ inputs=[custom_lora_input, selected_indices, loras_state, gallery], # ← loras_state causes SSRF error
46
+ outputs=[loras_state, gallery, error_display, custom_lora_input, selected_indices]
 
 
47
  )
48
 
49
  if __name__ == "__main__":
50
+ # Set global variable for working version
51
+ loras = sample_loras
52
  demo.launch()