Commit e625f20
committed
fix: allow subdirectory paths in loadStaticCaseData validation
The path traversal check rejected any filename containing `/`, which
blocked curriculum stages from loading data files in subdirectories
like `curriculum/first-sip/stage-1-goal.json`. Changed to only reject
absolute paths (starting with `/`) while still blocking `..` traversal.1 parent 4c9c4e8 commit e625f20
File tree
2 files changed
+13
-3
lines changed- actions
- src/__tests__/integration
2 files changed
+13
-3
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
14 | | - | |
| 14 | + | |
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
123 | 123 | | |
124 | 124 | | |
125 | 125 | | |
126 | | - | |
| 126 | + | |
127 | 127 | | |
128 | 128 | | |
129 | 129 | | |
130 | | - | |
| 130 | + | |
131 | 131 | | |
132 | 132 | | |
133 | 133 | | |
134 | 134 | | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
135 | 145 | | |
136 | 146 | | |
137 | 147 | | |
| |||
0 commit comments