MCPcopy Create free account
hub / github.com/colbymchenry/codegraph / validateProjectPath

Function validateProjectPath

src/utils.ts:175–204  ·  view source on GitHub ↗
(dirPath: string)

Source from the content-addressed store, hash-verified

173 * @returns An error message if invalid, or null if valid
174 */
175export function validateProjectPath(dirPath: string): string | null {
176 const resolved = path.resolve(dirPath);
177
178 // Block sensitive system directories
179 if (SENSITIVE_PATHS.has(resolved) || SENSITIVE_PATHS.has(resolved.toLowerCase())) {
180 return `Refusing to operate on sensitive system directory: ${resolved}`;
181 }
182
183 // Also block common sensitive home subdirectories
184 const homeDir = require('os').homedir();
185 const sensitiveHomeDirs = ['.ssh', '.gnupg', '.aws', '.config'];
186 for (const dir of sensitiveHomeDirs) {
187 const sensitivePath = path.join(homeDir, dir);
188 if (resolved === sensitivePath || resolved.startsWith(sensitivePath + path.sep)) {
189 return `Refusing to operate on sensitive directory: ${resolved}`;
190 }
191 }
192
193 // Verify it's a real directory
194 try {
195 const stats = fs.statSync(resolved);
196 if (!stats.isDirectory()) {
197 return `Path is not a directory: ${resolved}`;
198 }
199 } catch {
200 return `Path does not exist or is not accessible: ${resolved}`;
201 }
202
203 return null;
204}
205
206/**
207 * Safely parse JSON with a fallback value.

Callers 4

getCodeGraphMethod · 0.90
resolveProjectFileFunction · 0.90
security.test.tsFile · 0.90
mainFunction · 0.85

Calls 3

hasMethod · 0.80
resolveMethod · 0.65
joinMethod · 0.45

Tested by

no test coverage detected