BigPizzaV3/CodexPlusPlus · error
市场主题 {} 的来源地址协议无效
Error message
市场主题 {} 的来源地址协议无效 What it means
Security guard in validate_market_theme: theme.source_url parses as a URL but its scheme is not http or https. Non-web schemes (file:, ftp:, javascript:, etc.) are refused to prevent the client from being pointed at local or executable resources.
Source
Thrown at crates/codex-plus-core/src/dream_skin_market.rs:230
] {
if value.trim().is_empty() || value.len() > limit {
bail!("市场主题 {} 的{}无效", theme.id, label);
}
}
if theme.description.len() > 500 || theme.tags.len() > 12 {
bail!("市场主题 {} 的描述或标签数量超过限制", theme.id);
}
if theme
.tags
.iter()
.any(|tag| tag.trim().is_empty() || tag.len() > 32)
{
bail!("市场主题 {} 包含无效标签", theme.id);
}
let source = reqwest::Url::parse(&theme.source_url)
.with_context(|| format!("市场主题 {} 的来源地址无效", theme.id))?;
if !matches!(source.scheme(), "http" | "https") {
bail!("市场主题 {} 的来源地址协议无效", theme.id);
}
for path in [&theme.theme, &theme.image, &theme.preview] {
validate_market_path(path)?;
}
validate_sha256(&theme.theme_sha256)?;
validate_sha256(&theme.image_sha256)?;
Ok(())
}
fn market_http_client() -> anyhow::Result<reqwest::Client> {
Ok(reqwest::Client::builder()
.user_agent(format!(
"CodexPlusPlus-Themes/{}",
env!("CARGO_PKG_VERSION")
))
.connect_timeout(Duration::from_secs(8))
.timeout(Duration::from_secs(30))
.build()?)View on GitHub (pinned to f2074595a2)
Solutions
- Change source_url to an http(s) URL
- Remove or fix the theme entry in the manifest
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at crates/codex-plus-core/src/dream_skin_market.rs:230 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of BigPizzaV3/CodexPlusPlus@f2074595a2 (2026-08-23).
Data as JSON: /api/errors/912cdc61993008e9.
Report an issue: GitHub.