fix: skip traversal guard for bare root paths in /api/fs/list (#2109)

This commit is contained in:
Sparsh 2026-06-09 12:05:56 +05:30 • committed by GitHub
parent 74e81ba014
commit 093a6b71f6
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 8 additions and 6 deletions

View file

@ -569,7 +569,10 @@ export const handleFsListRequest = async (
res.status(400).json({ error: '"dir" must be an absolute path' });
return;
}
if (path.normalize(dir) !== path.resolve(dir)) {
// Skip the traversal guard for bare root directories (/ on Linux, C:\ on
// Windows) where path.normalize and path.resolve diverge on Windows.
const isRoot = dir === path.parse(dir).root;
if (!isRoot && path.normalize(dir) !== path.resolve(dir)) {
res.status(400).json({ error: '"dir" must not contain traversal sequences' });
return;
}

View file

@ -54,11 +54,10 @@ describe('GET /api/fs/list — handleFsListRequest', () => {
it('defaults to / when dir is omitted (linux server)', async () => {
const { status } = await invoke({});
if (process.platform === 'win32') {
expect(status).toBe(400);
} else {
expect(status).toBe(200);
}
// On Linux root / is the filesystem root; on Windows path.normalize('/')
// normalizes to \ while path.resolve('/') resolves to the CWD drive root.
// Our guard skips the traversal check for bare root paths.
expect(status).toBe(200);
});
it('returns 400 for a relative path', async () => {