Samin061 opened a new pull request, #74012: URL: https://github.com/apache/airflow/pull/74012
`ObjectStoragePath.copy()` delegates a recursive remote-to-local transfer straight to fsspec's `fs.get`, so object keys containing `..` segments (which anyone able to write to the source prefix controls) are followed verbatim and land outside the destination directory. This adds a containment check on the recursive remote-to-local branch that expands the source keys and refuses any whose resolved local path escapes the destination, matching the guards already used on the other sync-to-local paths. Non-recursive and same-store copies are untouched, so valid transfers behave exactly as before. This supersedes #69850, which was closed under the open-PR limit; its branch had drifted far behind `main` and could not be reopened, so this reopens the change rebased on current `main` with the regression tests. --- ##### Was generative AI tooling used to co-author this PR? - [X] Yes — Claude Code Generated-by: Claude Code following [the guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
