mirror of
https://github.com/luckyyzh/pi-agent-integrated.git
synced 2026-10-03 02:59:35 +00:00
feat: integrate Pi backend and Pi Web
This commit is contained in:
@@ -0,0 +1,27 @@
|
||||
import assert from "node:assert/strict";
|
||||
import fs from "node:fs";
|
||||
import os from "node:os";
|
||||
import path from "node:path";
|
||||
import test from "node:test";
|
||||
|
||||
async function loadSubject() {
|
||||
return import("./path-security.ts");
|
||||
}
|
||||
|
||||
test("rejects an existing path that escapes an allowed root through a symlink", async (t) => {
|
||||
const { isExistingPathWithinRoots, isPathWithinRoots } = await loadSubject();
|
||||
const base = fs.mkdtempSync(path.join(os.tmpdir(), "pi-web-file-access-"));
|
||||
t.after(() => fs.rmSync(base, { recursive: true, force: true }));
|
||||
const allowed = path.join(base, "allowed");
|
||||
const outside = path.join(base, "outside");
|
||||
fs.mkdirSync(allowed);
|
||||
fs.mkdirSync(outside);
|
||||
fs.writeFileSync(path.join(outside, "secret.txt"), "secret");
|
||||
const link = path.join(allowed, "link");
|
||||
fs.symlinkSync(outside, link, process.platform === "win32" ? "junction" : "dir");
|
||||
const target = path.join(link, "secret.txt");
|
||||
const roots = new Set([allowed]);
|
||||
|
||||
assert.equal(isPathWithinRoots(target, roots), true);
|
||||
assert.equal(isExistingPathWithinRoots(target, roots), false);
|
||||
});
|
||||
Reference in New Issue
Block a user