INNER CODE UNIT · Python

_safe_rel

Laurent00TT/PharosRAG · src/chunker/core.py:53

def _safe_rel(p):
    """SECURITY (seal review): an image_path must be a SAFE RELATIVE ref under the MinerU output root —
    reject absolute / UNC / drive paths, URL schemes (://), and '..' traversal, so a poisoned parse can't
    make the embed stage read an arbitrary file or SSRF off it. Returns the cleaned rel path, or None."""
    import posixpath
    if not isinstance(p, str) or not p.strip():
        return None
    q = p.strip().replace("\\", "/")
    if "://" in q or q.startswith("/") or re.match(r"^[A-Za-z]:", q):
        return None                                  # url scheme / absolute / UNC / windows drive letter
    norm = posixpath.normpath(q)
    if norm == ".." or norm.startswith("../") or norm.startswith("/"):
        return None                                  # traversal escaping the output root
    return norm


def _asset_desc(s, cap=800):
    """An image's VLM-extracted content (OCR text / mermaid / chart data) or alt-text, cleaned for

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…