import assert from "node:assert/strict"; import fs from "node:fs"; import os from "node:os"; import path from "node:path"; import test from "node:test"; async function loadSubject() { return import("./path-security.ts"); } test("rejects an existing path that escapes an allowed root through a symlink", async (t) => { const { isExistingPathWithinRoots, isPathWithinRoots } = await loadSubject(); const base = fs.mkdtempSync(path.join(os.tmpdir(), "pi-web-file-access-")); t.after(() => fs.rmSync(base, { recursive: true, force: true })); const allowed = path.join(base, "allowed"); const outside = path.join(base, "outside"); fs.mkdirSync(allowed); fs.mkdirSync(outside); fs.writeFileSync(path.join(outside, "secret.txt"), "secret"); const link = path.join(allowed, "link"); fs.symlinkSync(outside, link, process.platform === "win32" ? "junction" : "dir"); const target = path.join(link, "secret.txt"); const roots = new Set([allowed]); assert.equal(isPathWithinRoots(target, roots), true); assert.equal(isExistingPathWithinRoots(target, roots), false); });