fix(02): resolve symlinks before fixture and vars path checks (WR-07)

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Jakub Zych
2026-09-17 14:44:23 +02:00
parent 0ac9dc45d0
commit f7b81b9dd7
4 changed files with 57 additions and 3 deletions

View File

@@ -184,7 +184,20 @@ func materializeSidecar(base string, resp *Response) error {
if base != "" {
path = filepath.Join(base, resp.BodyFile)
}
raw, err := os.ReadFile(path)
resolved, err := resolvePath(path)
if err != nil {
return fmt.Errorf("tide: read body_file %s: %w", resp.BodyFile, err)
}
if base != "" {
root, err := resolvePath(base)
if err != nil {
return fmt.Errorf("tide: fixture dir: %w", err)
}
if resolved != root && !strings.HasPrefix(resolved, root+string(os.PathSeparator)) {
return fmt.Errorf("tide: body_file %q escapes the fixture directory", resp.BodyFile)
}
}
raw, err := os.ReadFile(resolved)
if err != nil {
return fmt.Errorf("tide: read body_file %s: %w", resp.BodyFile, err)
}
@@ -208,6 +221,9 @@ func validateSidecar(path string) error {
if clean == ".." || strings.HasPrefix(clean, "../") {
return fmt.Errorf("body_file %q escapes the fixture directory", path)
}
if _, err := resolvePath(path); err != nil {
return fmt.Errorf("body_file %q: %w", path, err)
}
return nil
}