-
Notifications
You must be signed in to change notification settings - Fork 753
Throw when copying from paths outside the context dir #1067
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
🦋 Changeset detectedLatest commit: 56b668f The changes in this PR will be included in the next version bump. This PR includes changesets to release 2 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: da296034db
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
packages/python-sdk/tests/async/template_async/test_stacktrace.py
Outdated
Show resolved
Hide resolved
packages/python-sdk/tests/async/template_async/test_stacktrace.py
Outdated
Show resolved
Hide resolved
jakubno
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
why can't we throw directly in .copy() command? Can't you resolve the path directly there? You want to work with the relative path ideally everywhere anyway?
packages/python-sdk/tests/shared/template/utils/test_is_safe_relative.py
Show resolved
Hide resolved
|
Cursor review |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
✅ Bugbot reviewed your changes and found no bugs!
Note
Strengthens path handling and safety in template
copyoperations.normalizePath/normalize_pathandisSafeRelativein JS/Python utils; normalize inputs and reject sources outside the context dirTemplate.copyto use normalized args and throw with caller stack trace when src escapes contextnormalizePath/isSafeRelativeWritten by Cursor Bugbot for commit 56b668f. This will update automatically on new commits. Configure here.