Spaces:
Running
Running
Update app.py
Browse files
app.py
CHANGED
|
@@ -1,34 +1,4 @@
|
|
| 1 |
-
|
| 2 |
-
@app.route('/proxy/<path:url>')
|
| 3 |
-
def proxy(url):
|
| 4 |
-
# Authorization header if user is logged in
|
| 5 |
-
headers = {}
|
| 6 |
-
if 'token' in session:
|
| 7 |
-
headers["Authorization"] = f"Bearer {session['token']}"
|
| 8 |
-
|
| 9 |
-
try:
|
| 10 |
-
# Parse URL to ensure it's safe
|
| 11 |
-
parsed_url = urlparse(url)
|
| 12 |
-
if not parsed_url.netloc.endswith('huggingface.co'):
|
| 13 |
-
return "Only Huggingface URLs are allowed", 403
|
| 14 |
-
|
| 15 |
-
# Make request to the target URL
|
| 16 |
-
response = requests.get(url, headers=headers, stream=True)
|
| 17 |
-
|
| 18 |
-
# Create response
|
| 19 |
-
resp = Response(
|
| 20 |
-
response.iter_content(chunk_size=10*1024),
|
| 21 |
-
content_type=response.headers.get('Content-Type')
|
| 22 |
-
)
|
| 23 |
-
|
| 24 |
-
# Remove headers that prevent iframe embedding
|
| 25 |
-
resp.headers.remove('X-Frame-Options')
|
| 26 |
-
resp.headers.remove('Content-Security-Policy')
|
| 27 |
-
|
| 28 |
-
return resp
|
| 29 |
-
except Exception as e:
|
| 30 |
-
print(f"Proxy error: {e}")
|
| 31 |
-
return f"Error: {str(e)}", 500from flask import Flask, render_template, request, redirect, url_for, jsonify, session, Response
|
| 32 |
import requests
|
| 33 |
import os
|
| 34 |
from datetime import timedelta
|
|
@@ -113,6 +83,40 @@ def validate_token(token):
|
|
| 113 |
|
| 114 |
return False, None
|
| 115 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 116 |
# Homepage route
|
| 117 |
@app.route('/')
|
| 118 |
def home():
|
|
@@ -198,7 +202,7 @@ if __name__ == '__main__':
|
|
| 198 |
with open('templates/index.html', 'w', encoding='utf-8') as f:
|
| 199 |
f.write('''
|
| 200 |
<!DOCTYPE html>
|
| 201 |
-
<html lang="
|
| 202 |
<head>
|
| 203 |
<meta charset="UTF-8">
|
| 204 |
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
|
|
| 1 |
+
from flask import Flask, render_template, request, redirect, url_for, jsonify, session, Response
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 2 |
import requests
|
| 3 |
import os
|
| 4 |
from datetime import timedelta
|
|
|
|
| 83 |
|
| 84 |
return False, None
|
| 85 |
|
| 86 |
+
# Proxy route to bypass X-Frame-Options
|
| 87 |
+
@app.route('/proxy/<path:url>')
|
| 88 |
+
def proxy(url):
|
| 89 |
+
# Authorization header if user is logged in
|
| 90 |
+
headers = {}
|
| 91 |
+
if 'token' in session:
|
| 92 |
+
headers["Authorization"] = f"Bearer {session['token']}"
|
| 93 |
+
|
| 94 |
+
try:
|
| 95 |
+
# Parse URL to ensure it's safe
|
| 96 |
+
parsed_url = urlparse(url)
|
| 97 |
+
if not parsed_url.netloc.endswith('huggingface.co'):
|
| 98 |
+
return "Only Huggingface URLs are allowed", 403
|
| 99 |
+
|
| 100 |
+
# Make request to the target URL
|
| 101 |
+
response = requests.get(url, headers=headers, stream=True)
|
| 102 |
+
|
| 103 |
+
# Create response
|
| 104 |
+
resp = Response(
|
| 105 |
+
response.iter_content(chunk_size=10*1024),
|
| 106 |
+
content_type=response.headers.get('Content-Type')
|
| 107 |
+
)
|
| 108 |
+
|
| 109 |
+
# Remove headers that prevent iframe embedding
|
| 110 |
+
if 'X-Frame-Options' in resp.headers:
|
| 111 |
+
resp.headers.remove('X-Frame-Options')
|
| 112 |
+
if 'Content-Security-Policy' in resp.headers:
|
| 113 |
+
resp.headers.remove('Content-Security-Policy')
|
| 114 |
+
|
| 115 |
+
return resp
|
| 116 |
+
except Exception as e:
|
| 117 |
+
print(f"Proxy error: {e}")
|
| 118 |
+
return f"Error: {str(e)}", 500
|
| 119 |
+
|
| 120 |
# Homepage route
|
| 121 |
@app.route('/')
|
| 122 |
def home():
|
|
|
|
| 202 |
with open('templates/index.html', 'w', encoding='utf-8') as f:
|
| 203 |
f.write('''
|
| 204 |
<!DOCTYPE html>
|
| 205 |
+
<html lang="ko">
|
| 206 |
<head>
|
| 207 |
<meta charset="UTF-8">
|
| 208 |
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|