INNER CODE UNIT · Python

_get_safe_filepath

existence-master/Sentient · src/server/mcp_hub/file_management/main.py:37

def _get_safe_filepath(filename: str) -> Path:
    """
    Constructs a full, safe path to a file within the temp directory and validates it.
    Prevents path traversal attacks.
    """
    # Base directory where all user files are stored
    base_dir = Path(FILE_MANAGEMENT_TEMP_DIR).resolve()
    
    # Create the full path by joining the base directory and the relative filename
    # The filename from the agent already includes the user's subdirectory, e.g., "user-id/report.pdf"
    full_path = (base_dir / filename).resolve()
    
    # SECURITY CHECK: Ensure the resolved path is still inside the base directory
    if base_dir not in full_path.parents:
        raise ToolError("Access denied: Path traversal attempt detected.")

    return full_path

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…