INNER CODE UNIT · Python
_get_safe_filepath
existence-master/Sentient · src/server/mcp_hub/file_management/main.py:37
def _get_safe_filepath(filename: str) -> Path:
"""
Constructs a full, safe path to a file within the temp directory and validates it.
Prevents path traversal attacks.
"""
# Base directory where all user files are stored
base_dir = Path(FILE_MANAGEMENT_TEMP_DIR).resolve()
# Create the full path by joining the base directory and the relative filename
# The filename from the agent already includes the user's subdirectory, e.g., "user-id/report.pdf"
full_path = (base_dir / filename).resolve()
# SECURITY CHECK: Ensure the resolved path is still inside the base directory
if base_dir not in full_path.parents:
raise ToolError("Access denied: Path traversal attempt detected.")
return full_path