fix(02): resolve symlinks before fixture and vars path checks (WR-07)
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
18
tide/flow.go
18
tide/flow.go
@@ -184,7 +184,20 @@ func materializeSidecar(base string, resp *Response) error {
|
||||
if base != "" {
|
||||
path = filepath.Join(base, resp.BodyFile)
|
||||
}
|
||||
raw, err := os.ReadFile(path)
|
||||
resolved, err := resolvePath(path)
|
||||
if err != nil {
|
||||
return fmt.Errorf("tide: read body_file %s: %w", resp.BodyFile, err)
|
||||
}
|
||||
if base != "" {
|
||||
root, err := resolvePath(base)
|
||||
if err != nil {
|
||||
return fmt.Errorf("tide: fixture dir: %w", err)
|
||||
}
|
||||
if resolved != root && !strings.HasPrefix(resolved, root+string(os.PathSeparator)) {
|
||||
return fmt.Errorf("tide: body_file %q escapes the fixture directory", resp.BodyFile)
|
||||
}
|
||||
}
|
||||
raw, err := os.ReadFile(resolved)
|
||||
if err != nil {
|
||||
return fmt.Errorf("tide: read body_file %s: %w", resp.BodyFile, err)
|
||||
}
|
||||
@@ -208,6 +221,9 @@ func validateSidecar(path string) error {
|
||||
if clean == ".." || strings.HasPrefix(clean, "../") {
|
||||
return fmt.Errorf("body_file %q escapes the fixture directory", path)
|
||||
}
|
||||
if _, err := resolvePath(path); err != nil {
|
||||
return fmt.Errorf("body_file %q: %w", path, err)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user