MCPcopy Create free account
hub / github.com/Kilo-Org/cloud / resolveSafePath

Function resolveSafePath

services/kiloclaw/controller/src/safe-path.ts:15–35  ·  view source on GitHub ↗
(relativePath: string, rootDir: string)

Source from the content-addressed store, hash-verified

13 * `verifyCanonicalized` after confirming the path exists on disk).
14 */
15export function resolveSafePath(relativePath: string, rootDir: string): string {
16 if (!relativePath) {
17 throw new SafePathError('Path must not be empty');
18 }
19
20 if (relativePath.includes('\0')) {
21 throw new SafePathError('Path must not contain null bytes');
22 }
23
24 if (path.isAbsolute(relativePath)) {
25 throw new SafePathError('Path must be relative');
26 }
27
28 const resolved = path.resolve(rootDir, relativePath);
29
30 if (resolved !== rootDir && !resolved.startsWith(rootDir + '/')) {
31 throw new SafePathError('Path escapes root directory');
32 }
33
34 return resolved;
35}
36
37/**
38 * Verify that a resolved path, after canonicalization via realpath, still

Callers 7

safe-path.test.tsFile · 0.90
resolveAndValidateFileFunction · 0.90
registerFileRoutesFunction · 0.90

Calls

no outgoing calls

Tested by

no test coverage detected