INNER CODE UNIT · Python
_confine_path
tiliondev/fortress · mcp/server.py:117
def _confine_path(path: str | None, suffix: str) -> str:
"""Confine a tool-supplied write path to the sandbox root — blocks path
traversal / overwriting arbitrary files (e.g. ~/.ssh/authorized_keys). Only the
basename is used. Set TILION_MCP_ALLOW_ANY_PATH=1 to write anywhere (trusted
local use). A None path yields a fresh temp name in the root."""
import tempfile
root = _write_root()
if _env("MCP_ALLOW_ANY_PATH", "0") == "1" and path:
return path
if not path:
fd, p = tempfile.mkstemp(suffix=suffix, prefix="tilion_", dir=root)
os.close(fd)
return p
name = os.path.basename(path) or ("out" + suffix)
if not os.path.splitext(name)[1]:
name += suffix
return os.path.join(root, name)