INNER CODE UNIT · Python
_norm
Laurent00TT/PharosRAG · src/chunker/core.py:49
def _norm(text):
return re.sub(r"\s+", " ", (text or "").strip())
def _safe_rel(p):
"""SECURITY (seal review): an image_path must be a SAFE RELATIVE ref under the MinerU output root —
reject absolute / UNC / drive paths, URL schemes (://), and '..' traversal, so a poisoned parse can't
make the embed stage read an arbitrary file or SSRF off it. Returns the cleaned rel path, or None."""
import posixpath
if not isinstance(p, str) or not p.strip():
return None
q = p.strip().replace("\\", "/")
if "://" in q or q.startswith("/") or re.match(r"^[A-Za-z]:", q):
return None # url scheme / absolute / UNC / windows drive letter
norm = posixpath.normpath(q)
if norm == ".." or norm.startswith("../") or norm.startswith("/"):
return None # traversal escaping the output root
return norm