Files

28 lines
1.1 KiB
JavaScript

import assert from "node:assert/strict";
import fs from "node:fs";
import os from "node:os";
import path from "node:path";
import test from "node:test";
async function loadSubject() {
return import("./path-security.ts");
}
test("rejects an existing path that escapes an allowed root through a symlink", async (t) => {
const { isExistingPathWithinRoots, isPathWithinRoots } = await loadSubject();
const base = fs.mkdtempSync(path.join(os.tmpdir(), "pi-web-file-access-"));
t.after(() => fs.rmSync(base, { recursive: true, force: true }));
const allowed = path.join(base, "allowed");
const outside = path.join(base, "outside");
fs.mkdirSync(allowed);
fs.mkdirSync(outside);
fs.writeFileSync(path.join(outside, "secret.txt"), "secret");
const link = path.join(allowed, "link");
fs.symlinkSync(outside, link, process.platform === "win32" ? "junction" : "dir");
const target = path.join(link, "secret.txt");
const roots = new Set([allowed]);
assert.equal(isPathWithinRoots(target, roots), true);
assert.equal(isExistingPathWithinRoots(target, roots), false);
});