* refac(routers): reject external URLs in profile/model image handlers * refac(ui): centralize image URL validation in safeImageUrl helper * refac(auths): make signout POST-only * refac: gate external profile image redirect behind ENABLE_PROFILE_IMAGE_URL_FORWARDING Restore the 302 redirect for external http(s) profile image URLs in the user and model profile-image endpoints, but gate it behind a new ENABLE_PROFILE_IMAGE_URL_FORWARDING env flag (default: True). Existing deployments that rely on external profile image forwarding continue to work unchanged. Operators who want to suppress the redirect (to prevent client-side IP/UA/Referer leaks) can set the flag to False.
16 lines
365 B
Svelte
16 lines
365 B
Svelte
<script lang="ts">
|
|
import { WEBUI_BASE_URL } from '$lib/constants';
|
|
import { safeImageUrl } from '$lib/utils/safeImageUrl';
|
|
|
|
export let className = 'size-8';
|
|
export let src = `${WEBUI_BASE_URL}/static/favicon.png`;
|
|
</script>
|
|
|
|
<img
|
|
aria-hidden="true"
|
|
src={safeImageUrl(src)}
|
|
class=" {className} object-cover rounded-full"
|
|
alt="profile"
|
|
draggable="false"
|
|
/>
|