| 765 | } |
| 766 | |
| 767 | bool cbm_workspace_manifest_allows(const char *cache_dir, const char *home_dir, |
| 768 | const char *project_root, const char *candidate) { |
| 769 | if (!candidate || !candidate[0]) { |
| 770 | return false; |
| 771 | } |
| 772 | cbm_ws_manifest_t m; |
| 773 | if (!cbm_workspace_manifest_read(project_root, &m) || !m.present) { |
| 774 | return false; |
| 775 | } |
| 776 | if (!cbm_workspace_manifest_is_approved(cache_dir, project_root, &m)) { |
| 777 | return false; |
| 778 | } |
| 779 | for (int i = 0; i < m.count; i++) { |
| 780 | /* Re-classify at use time as well as at approval time: the credential list |
| 781 | * may have grown since, and a stored approval must not outrank it. */ |
| 782 | if (cbm_workspace_classify_root(m.entries[i], home_dir, cache_dir) != CBM_WS_ALLOW) { |
| 783 | continue; |
| 784 | } |
| 785 | if (cbm_path_within_root(m.entries[i], candidate)) { |
| 786 | return true; |
| 787 | } |
| 788 | } |
| 789 | return false; |
| 790 | } |
nothing calls this directly
no test coverage detected