Samin061 opened a new pull request, #74012:
URL: https://github.com/apache/airflow/pull/74012

   `ObjectStoragePath.copy()` delegates a recursive remote-to-local transfer 
straight to fsspec's `fs.get`, so object keys containing `..` segments (which 
anyone able to write to the source prefix controls) are followed verbatim and 
land outside the destination directory. This adds a containment check on the 
recursive remote-to-local branch that expands the source keys and refuses any 
whose resolved local path escapes the destination, matching the guards already 
used on the other sync-to-local paths. Non-recursive and same-store copies are 
untouched, so valid transfers behave exactly as before.
   
   This supersedes #69850, which was closed under the open-PR limit; its branch 
had drifted far behind `main` and could not be reopened, so this reopens the 
change rebased on current `main` with the regression tests.
   
   ---
   
   ##### Was generative AI tooling used to co-author this PR?
   
   - [X] Yes — Claude Code
   
   Generated-by: Claude Code following [the 
guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to