Skip to main content

is_safe_relative_path

Function is_safe_relative_path 

Source
pub fn is_safe_relative_path(path: &str) -> bool
Expand description

Whether path, joined to a directory, is sure to stay inside it.

Every component has to be a plain name. .. climbs out, and a root, a drive letter or a UNC share makes join drop the directory altogether: base.join("C:\\x") is just C:\x. A leading ./ is refused as well; nothing we link to starts with one. On Windows no component may hold a : either. No file name can, so past a drive letter it could only pick an NTFS alternate data stream.

Meant for paths taken from a request, before they are joined to the recipe directory. The check is purely lexical on purpose: merely looking up \\host\share on disk makes Windows connect to that host and hand it the user’s NTLM hash.