MCPcopy Create free account
hub / github.com/atomicdotdev/atomic / validate_session_id

Function validate_session_id

atomic-agent/src/turn/session.rs:674–703  ·  view source on GitHub ↗

Validate a session ID to prevent path traversal. Rejects IDs containing `..`, `/`, `\`, or null bytes.

(session_id: &str)

Source from the content-addressed store, hash-verified

672///
673/// Rejects IDs containing `..`, `/`, `\`, or null bytes.
674fn validate_session_id(session_id: &str) -> AgentResult<()> {
675 if session_id.is_empty() {
676 return Err(AgentError::SessionIdInvalid {
677 session_id: "(empty)".to_string(),
678 });
679 }
680
681 if session_id.contains("..")
682 || session_id.contains('/')
683 || session_id.contains('\\')
684 || session_id.contains('\0')
685 {
686 return Err(AgentError::SessionIdInvalid {
687 session_id: session_id.to_string(),
688 });
689 }
690
691 // Reject very long session IDs (filesystem path limits)
692 if session_id.len() > 255 {
693 return Err(AgentError::SessionIdInvalid {
694 session_id: format!(
695 "{}... (too long: {} chars)",
696 &session_id[..20],
697 session_id.len()
698 ),
699 });
700 }
701
702 Ok(())
703}
704
705// Tests
706

Callers 5

loadMethod · 0.85
saveMethod · 0.85
clearMethod · 0.85

Calls 3

is_emptyMethod · 0.45
containsMethod · 0.45
lenMethod · 0.45

Tested by 2