diff --git a/.changeset/eager-badgers-bark.md b/.changeset/eager-badgers-bark.md index 7882a6145..ab8071b6a 100644 --- a/.changeset/eager-badgers-bark.md +++ b/.changeset/eager-badgers-bark.md @@ -1,5 +1,5 @@ --- type: Changed -pr: 0 +pr: 4672 --- -**The path-containment predicate is now a single exported seam** — `security.cjs` no longer exports `validatePath`; `assertWithinRoot` (throws), `tryWithinRoot` (returns null) and `requireSafePath` are the only containment exports, and all three return a branded `ContainedPath` so a validated path cannot be silently swapped for an unvalidated one. The per-call-site `{ allowAbsolute: true }` flag is replaced by the named `PathAcceptance` policy, which states what it actually permits: an absolute path outside the root was always rejected and still is. The traversal rejection text `Path escapes allowed directory: is outside ` is preserved verbatim, and no command changes what it accepts or rejects. Three rejection MESSAGES are reworded, none of which now reveals a host path it previously hid: `state.cts`'s `