INNER CODE UNIT · TypeScript

hasSafeConfigArtifactParent

ZaxbyHub/opencode-swarm · src/cli/index.ts:132

function hasSafeConfigArtifactParent(
	resolved: string,
	configuredDir?: string,
): boolean {
	if (configuredDir !== undefined) {
		return isExactConfiguredConfigChild(resolved, configuredDir);
	}
	return path.basename(path.dirname(resolved)) === path.basename(CONFIG_DIR);
}

// Issue #675 hardening — round 3 (depth-based guard replaces home-containment
// after critic's cross-platform CI regression finding).
export function isSafeCachePath(p: string): boolean {
	const resolved = path.resolve(p);
	const home = path.resolve(os.homedir());
	// 1. Catastrophic-path floor.
	if (resolved === '/' || resolved === home || resolved.length <= home.length) {
		return false;

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…