INNER CODE UNIT · Python

_write_root

tiliondev/fortress · mcp/server.py:108

def _write_root() -> str:
    """The directory tool-written files are confined to. Override with
    TILION_MCP_WRITE_DIR; defaults to <tempdir>/tilion-mcp."""
    import tempfile
    root = _env("MCP_WRITE_DIR") or os.path.join(tempfile.gettempdir(), "tilion-mcp")
    os.makedirs(root, exist_ok=True)
    return os.path.abspath(root)


def _confine_path(path: str | None, suffix: str) -> str:
    """Confine a tool-supplied write path to the sandbox root — blocks path
    traversal / overwriting arbitrary files (e.g. ~/.ssh/authorized_keys). Only the
    basename is used. Set TILION_MCP_ALLOW_ANY_PATH=1 to write anywhere (trusted
    local use). A None path yields a fresh temp name in the root."""
    import tempfile
    root = _write_root()
    if _env("MCP_ALLOW_ANY_PATH", "0") == "1" and path:
        return path

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…