fix(ci): align lint-safe security paths

This commit is contained in:
elky
2026-09-05 03:19:53 +08:00
parent f5e1420ee6
commit 33d5cd5993
45 changed files with 180 additions and 132 deletions
+5 -3
View File
@@ -3913,9 +3913,11 @@ fn chatgpt_web_blocked_features(value: &serde_json::Value) -> Vec<String> {
.flatten()
.filter_map(serde_json::Value::as_str)
.any(chatgpt_web_is_image_quota_feature);
image_blocked
.then(|| vec!["image_generation".to_string()])
.unwrap_or_default()
if image_blocked {
vec!["image_generation".to_string()]
} else {
Vec::new()
}
}
pub fn parse_chatgpt_web_conversation_init_response(
+6 -11
View File
@@ -468,7 +468,7 @@ fn normalized_proxy_url_identity(value: &str) -> Option<(String, String, u16)> {
return None;
}
let host = parsed.host_str()?.to_ascii_lowercase();
let port = parsed.port().or_else(|| match scheme.as_str() {
let port = parsed.port().or(match scheme.as_str() {
"http" => Some(80),
"https" => Some(443),
"socks5" | "socks5h" => Some(1080),
@@ -629,9 +629,7 @@ fn project_chatgpt_web_metadata(value: &Value) -> Value {
// This is an opaque idempotency key, not a diagnostic or credential. Keep it
// bounded and token-safe so quota request de-duplication survives persistence.
copy_safe_token_string_or_null(source, &mut projected, "image_quota_last_local_request_key");
for field in ["image_quota_blocked"] {
copy_json_bool_or_null(source, &mut projected, field);
}
copy_json_bool_or_null(source, &mut projected, "image_quota_blocked");
for field in [
"default_model_slug",
"plan_type",
@@ -1757,9 +1755,7 @@ fn trimmed_string_field(object: &Map<String, Value>, key: &str) -> Option<String
fn sanitize_network_url(value: &str) -> Option<String> {
let value = value.trim();
let mut parsed = url::Url::parse(value).ok()?;
if parsed.host_str().is_none() {
return None;
}
parsed.host_str()?;
parsed.set_username("").ok()?;
parsed.set_password(None).ok()?;
parsed.set_query(None);
@@ -1916,14 +1912,13 @@ fn body_path_key_segments(path: &str) -> Vec<String> {
.trim()
.trim_matches(['\'', '"'])
.to_string();
if !inner.is_empty()
if (!inner.is_empty()
&& inner != "*"
&& inner.parse::<isize>().is_err()
&& !inner.contains('-')
&& !inner.contains('-'))
|| inner.contains(|character: char| character.is_ascii_alphabetic())
{
segments.push(inner);
} else if inner.contains(|character: char| character.is_ascii_alphabetic()) {
segments.push(inner);
}
index = close + 1;
}