Skip to main content

validate_file_path

Function validate_file_path 

Source
pub fn validate_file_path(path: &str) -> Result<(), ValidationError>
Expand description

Enforces that a file_path is safe to join onto a memory directory on any machine that later pulls it.

A pulled file is written to disk by whoever fetches it, so a bad path here is not merely invalid data — it is a write outside the memory directory on someone else’s machine. Hence checking on the way in (server) as well as on the way out (client).

Rejection is per-segment, not by substring: a filename like ..config.md is perfectly legitimate and must not be caught, while an a/../../b segment must be. (The Node server used a substring check and wrongly rejected the former.)

assert!(validate_file_path("topics/auth/tokens.md").is_ok());
assert!(validate_file_path("..config.md").is_ok());
assert_eq!(
    validate_file_path("../outside.md"),
    Err(ValidationError::FilePathTraversal),
);