Lines 903-943text
904 log("no notes in the package: page and e-mail skipped")
905 return json.dumps(report)
906 page_missing = not _blob_exists(f"{safe_show}/{ep}.html")
907 charts_missing = not _blob_exists(f"{safe_show}/{ep}_chart1.png")
908 email_wanted = send_email and RESEND_API_KEY and not (read_meta(safe_show, ep) or {}).get("email_sent")
909 if not (page_missing or charts_missing or email_wanted):
910 log("page, charts and e-mail already done")
911 return json.dumps(report)
913 work = tempfile.mkdtemp(prefix="finalize-")
915 tk_version = _resolve_version(TOOLKIT_PKG, "latest")
916 for f in TOOLKIT_FILES:
917 open(os.path.join(work, f), "wb").write(_fetch(f"{CDN}/{TOOLKIT_PKG}@{tk_version}/{f}", 5))
918 for f in (notes, "covered.md", "glossary.md"):
920 open(os.path.join(work, f), "wb").write(_fetch(f"{base}/{f}", 5))
921 title, dek = item["title"], item["summary"]
922 date = _pretty_date(item["pubdate"])
923 cmd = ["python3", "build_page.py", "--notes", notes, "--number", str(n),
924 "--title", title, "--dek", dek, "--audio-url", audio_url,
925 "--duration", str(duration), "--date", date,
926 "--out", f"{ep}.html", "--charts-prefix", f"{ep}_chart"]
927 r = subprocess.run(cmd, cwd=work, capture_output=True, text=True, timeout=300)
HighAi Review Evidence
It executes the downloaded build_page.py and build_email.py with Python, allowing a later registry release to run code on the server.
server.pyView on unpkg · L923 928 if r.returncode != 0:
929 report["error"] = f"build_page failed: {r.stderr[-300:]}"
930 return json.dumps(report)
931 charts = sorted(f for f in os.listdir(work) if re.fullmatch(rf"{ep}_chart\d+\.png", f))
932 if page_missing or charts_missing:
933 upload_public(open(os.path.join(work, f"{ep}.html"), "rb").read(),
934 f"{safe_show}/{ep}.html", content_type="text/html; charset=utf-8",
935 cache_control="public, max-age=300")
937 upload_public(open(os.path.join(work, c), "rb").read(), f"{safe_show}/{c}",
938 content_type="image/png", cache_control="public, max-age=86400")
939 log(f"page published with {len(charts)} chart(s): {page_url}")
941 chart_urls = ",".join(f"https://storage.googleapis.com/{GCS_BUCKET}/{safe_show}/{c}" for c in charts)
942 cmd = ["python3", "build_email.py", "--notes", notes, "--number", str(n),
943 "--title", title, "--dek", dek, "--audio-url", audio_url,