oscerd commented on PR #27119:
URL: https://github.com/apache/camel/pull/27119#issuecomment-5947895734
Thanks, both points are addressed in `bcb3ff8d722e`.
**1. No confinement without a static directory.** You were right that the
object name is untrusted whatever the template looks like. The consumer now
checks the object name itself in every branch: an absolute name (a leading `/`
or `\`, or a drive letter such as `C:`) and a name with a `..` path segment are
rejected, even when the name would normalize back inside the directory. On top
of that, a fully dynamic template has its relative result checked lexically
against the working directory. That catches an object name that only becomes a
parent segment once joined with the template, for example `.${file:name}` with
an object named `./file.txt`, which resolves to `../file.txt`.
An absolute result that comes from the route's own expression is
deliberately not confined, since that part is configured by the route author.
Your two examples, `${file:name}` with `../../home/app/.ssh/authorized_keys`
and `prefix-${file:name}` with `/../../x`, are now tests.
**2. Windows drive root.** `staticDirectoryPrefix` now keeps the separator
of a drive root, so `C:\${file:name}` and `C:/${file:name}` confine to `C:\`
and `C:/` rather than the drive-relative `C:`.
The 4.23 upgrade-guide entry is rewritten accordingly. It no longer says the
fully dynamic form is unconfined.
_Claude Code on behalf of oscerd_
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]