pub fn validate_file_path(path: &str) -> Result<(), ValidationError>Expand description
Enforces that a file_path is safe to join onto a memory directory on
any machine that later pulls it.
A pulled file is written to disk by whoever fetches it, so a bad path here is not merely invalid data — it is a write outside the memory directory on someone else’s machine. Hence checking on the way in (server) as well as on the way out (client).
Rejection is per-segment, not by substring: a filename like ..config.md
is perfectly legitimate and must not be caught, while an a/../../b
segment must be. (The Node server used a substring check and wrongly
rejected the former.)
assert!(validate_file_path("topics/auth/tokens.md").is_ok());
assert!(validate_file_path("..config.md").is_ok());
assert_eq!(
validate_file_path("../outside.md"),
Err(ValidationError::FilePathTraversal),
);