Skip to main content

check_data_input_paths

Function check_data_input_paths 

Source
pub fn check_data_input_paths(
    inputs: &BTreeMap<String, Value>,
) -> Result<(), String>
Expand description

Check every key in a poke’s payload is a path that stays inside the workload. Returns the offending key on the first violation.

A poke is remote input, so an unchecked key is an arbitrary-file write: /etc/x, ../../secrets.json and a bare `` would all escape the workload the bearer authorizes. Only plain relative components are accepted — no root, no prefix, no .., no ..