INNER CODE UNIT · TypeScript
hasSafeConfigArtifactParent
ZaxbyHub/opencode-swarm · src/cli/index.ts:132
function hasSafeConfigArtifactParent(
resolved: string,
configuredDir?: string,
): boolean {
if (configuredDir !== undefined) {
return isExactConfiguredConfigChild(resolved, configuredDir);
}
return path.basename(path.dirname(resolved)) === path.basename(CONFIG_DIR);
}
// Issue #675 hardening — round 3 (depth-based guard replaces home-containment
// after critic's cross-platform CI regression finding).
export function isSafeCachePath(p: string): boolean {
const resolved = path.resolve(p);
const home = path.resolve(os.homedir());
// 1. Catastrophic-path floor.
if (resolved === '/' || resolved === home || resolved.length <= home.length) {
return false;