mirror of
https://github.com/iptv-org/iptv
synced 2026-09-06 03:50:47 -04:00
fix: harden getStoragePath and keep CRLF endings
- Normalize the returned path to forward slashes so it matches what Storage.list() (glob) returns, instead of leaking `\` on Windows. - Treat the storage root itself as "not inside", so passing a directory no longer yields an empty path that Storage.load() would open as a dir. - Extract the containment check into isInsideDirectory() and drop the redundant isAbsolute(filepath) branch (path.resolve already handles it). - Restore the repository's CRLF line endings in the nested fixture.
This commit is contained in:
+17
-12
@@ -53,24 +53,29 @@ export function normalizeURL(url: string): string {
|
||||
}
|
||||
}
|
||||
|
||||
function isInsideDirectory(rootDir: string, target: string): boolean {
|
||||
const relative = path.relative(rootDir, target)
|
||||
|
||||
return (
|
||||
relative !== '' &&
|
||||
relative !== '..' &&
|
||||
!relative.startsWith(`..${path.sep}`) &&
|
||||
!path.isAbsolute(relative)
|
||||
)
|
||||
}
|
||||
|
||||
export function getStoragePath(filepath: string, rootDir: string): string {
|
||||
const root = path.resolve(rootDir)
|
||||
const candidate = path.resolve(filepath)
|
||||
const candidateRelative = path.relative(root, candidate)
|
||||
const target =
|
||||
path.isAbsolute(filepath) ||
|
||||
(candidateRelative !== '..' &&
|
||||
!candidateRelative.startsWith(`..${path.sep}`) &&
|
||||
!path.isAbsolute(candidateRelative))
|
||||
? candidate
|
||||
: path.resolve(root, filepath)
|
||||
const relative = path.relative(root, target)
|
||||
const fromWorkspace = path.resolve(filepath)
|
||||
const target = isInsideDirectory(root, fromWorkspace)
|
||||
? fromWorkspace
|
||||
: path.resolve(root, filepath)
|
||||
|
||||
if (relative === '..' || relative.startsWith(`..${path.sep}`) || path.isAbsolute(relative)) {
|
||||
if (!isInsideDirectory(root, target)) {
|
||||
throw new Error(`Filepath "${filepath}" is outside the storage directory`)
|
||||
}
|
||||
|
||||
return relative
|
||||
return path.relative(root, target).split(path.sep).join('/')
|
||||
}
|
||||
|
||||
export function truncate(string: string, limit: number = 100) {
|
||||
|
||||
Reference in New Issue
Block a user