Skip to content

Keep preview symlink targets inside the generated site - #735

Open
Chessing234 wants to merge 1 commit into
teorth:mainfrom
Chessing234:codex/analysis-preview-symlink-containment
Open

Chessing234 wants to merge 1 commit into
teorth:mainfrom
Chessing234:codex/analysis-preview-symlink-containment

Conversation

@Chessing234

Copy link
Copy Markdown
Contributor

The preview server's lexical path check rejects .. escapes but follows symlinks outside the generated site when serving files. Resolve both the site root and candidate path before checking containment, so an external symlink target is rejected while internal links and a symlinked checkout continue to work.

Validation: an external-link fixture is served by the baseline and rejected after the fix; the internal-link/symlinked-root case still passes. Both unittest cases and Python compilation pass. Open and recently closed PRs were checked for symlink containment; no overlap. Existing preview PRs change routing, working-directory anchoring, and concurrency rather than this helper. git diff --check passes.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant