INNER CODE UNIT · Rust

is_safe_relative_path

ovexro/dockpanel · panel/backend/src/routes/mod.rs:253

pub fn is_safe_relative_path(path: &str) -> bool {
    !path.is_empty()
        && !path.contains('\0')
        && !path.contains("..")
        && !path.starts_with('/')
        && !path.contains('\\')
        && path.len() <= 4096
}

/// Reduce ordinary shell quoting/escaping so keyword-blocklist matching sees
/// what the shell will actually run, not what was literally typed —
/// `r'm' -rf /` and `w\get` contain no "rm -rf /"/"wget" substring, but the
/// real shell this command eventually runs through (`sh -c` in
/// `git_build.rs::run_hook` on the agent side) strips the quotes/backslashes
/// before exec. Mirrors `dockpanel-agent`'s `command_filter::normalize_for_blocklist`,
/// which this crate has no dependency path to reuse directly.
fn normalize_for_blocklist(cmd: &str) -> String {
    let mut out = String::with_capacity(cmd.len());

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…