mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-08-01 16:58:06 +00:00
fix(dev-server): inline normpath containment barrier before render
CodeQL doesn't credit the sanitization inside find_plugin_dir along this flow; apply its documented barrier (normpath + startswith against the allowed roots) inline in _parse_render_request, on the exact path that reaches the render/load sinks. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FqzC1nzTWL4kaqgMaQZFam
This commit is contained in:
@@ -264,6 +264,16 @@ def _parse_render_request(data):
|
||||
if not plugin_dir:
|
||||
raise LookupError(f'Plugin not found: {plugin_id}')
|
||||
|
||||
# Path-injection barrier: normalize (no symlink resolution — dev plugins
|
||||
# are commonly symlinked into plugins/) and require the directory to sit
|
||||
# inside one of the plugin search dirs before any file access.
|
||||
normalized = os.path.normpath(str(plugin_dir))
|
||||
allowed_roots = [os.path.normpath(str(d)) for d in get_search_dirs()]
|
||||
if not any(normalized == root or normalized.startswith(root + os.sep)
|
||||
for root in allowed_roots):
|
||||
raise LookupError(f'Plugin not found: {plugin_id}')
|
||||
plugin_dir = Path(normalized)
|
||||
|
||||
manifest_path = plugin_dir / 'manifest.json'
|
||||
with open(manifest_path, 'r') as f:
|
||||
manifest = json.load(f)
|
||||
|
||||
Reference in New Issue
Block a user