oscerd commented on PR #27119:
URL: https://github.com/apache/camel/pull/27119#issuecomment-5947895734

   Thanks, both points are addressed in `bcb3ff8d722e`.
   
   **1. No confinement without a static directory.** You were right that the 
object name is untrusted whatever the template looks like. The consumer now 
checks the object name itself in every branch: an absolute name (a leading `/` 
or `\`, or a drive letter such as `C:`) and a name with a `..` path segment are 
rejected, even when the name would normalize back inside the directory. On top 
of that, a fully dynamic template has its relative result checked lexically 
against the working directory. That catches an object name that only becomes a 
parent segment once joined with the template, for example `.${file:name}` with 
an object named `./file.txt`, which resolves to `../file.txt`.
   
   An absolute result that comes from the route's own expression is 
deliberately not confined, since that part is configured by the route author. 
Your two examples, `${file:name}` with `../../home/app/.ssh/authorized_keys` 
and `prefix-${file:name}` with `/../../x`, are now tests.
   
   **2. Windows drive root.** `staticDirectoryPrefix` now keeps the separator 
of a drive root, so `C:\${file:name}` and `C:/${file:name}` confine to `C:\` 
and `C:/` rather than the drive-relative `C:`.
   
   The 4.23 upgrade-guide entry is rewritten accordingly. It no longer says the 
fully dynamic form is unconfined.
   
   _Claude Code on behalf of oscerd_
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to