mirror of
https://github.com/luckyyzh/pi-agent-integrated.git
synced 2026-10-03 11:09:34 +00:00
28 lines
1.1 KiB
JavaScript
28 lines
1.1 KiB
JavaScript
import assert from "node:assert/strict";
|
|
import fs from "node:fs";
|
|
import os from "node:os";
|
|
import path from "node:path";
|
|
import test from "node:test";
|
|
|
|
async function loadSubject() {
|
|
return import("./path-security.ts");
|
|
}
|
|
|
|
test("rejects an existing path that escapes an allowed root through a symlink", async (t) => {
|
|
const { isExistingPathWithinRoots, isPathWithinRoots } = await loadSubject();
|
|
const base = fs.mkdtempSync(path.join(os.tmpdir(), "pi-web-file-access-"));
|
|
t.after(() => fs.rmSync(base, { recursive: true, force: true }));
|
|
const allowed = path.join(base, "allowed");
|
|
const outside = path.join(base, "outside");
|
|
fs.mkdirSync(allowed);
|
|
fs.mkdirSync(outside);
|
|
fs.writeFileSync(path.join(outside, "secret.txt"), "secret");
|
|
const link = path.join(allowed, "link");
|
|
fs.symlinkSync(outside, link, process.platform === "win32" ? "junction" : "dir");
|
|
const target = path.join(link, "secret.txt");
|
|
const roots = new Set([allowed]);
|
|
|
|
assert.equal(isPathWithinRoots(target, roots), true);
|
|
assert.equal(isExistingPathWithinRoots(target, roots), false);
|
|
});
|