INNER CODE UNIT · JavaScript
assertSafeArchiveEntry
agent-sh/agentsys · lib/binary/index.js:292
function assertSafeArchiveEntry(entry) {
if (!entry || typeof entry !== 'string') {
throw new Error('Refusing to extract archive with empty entry name');
}
const name = entry.replace(/\\/g, '/').trim();
if (name.length === 0) {
throw new Error('Refusing to extract archive with empty entry name');
}
if (name.startsWith('//')) {
throw new Error('Refusing to extract archive with UNC entry: ' + entry);
}
if (name.startsWith('/')) {
throw new Error('Refusing to extract archive with absolute entry: ' + entry);
}
if (/^[A-Za-z]:[\\/]/.test(entry)) {
throw new Error('Refusing to extract archive with Windows absolute entry: ' + entry);
}
const parts = name.split('/').filter(function(p) { return p.length > 0; });