fix(work): import hashlib and wire heal subparser into main CLI

This commit is contained in:
operator
2026-10-09 23:13:43 +00:00
parent c3b4b1cd28
commit f75977ca6e
202 changed files with 4185 additions and 4142 deletions
+10
View File
@@ -48,6 +48,14 @@ MD_ACCOUNT_RE = re.compile(r"^[A-Za-z0-9][A-Za-z0-9_-]{0,31}$")
MD_FILENAME_RE = re.compile(r"^[A-Za-z0-9_.-]{1,128}$")
MD_SUBPATH_RE = re.compile(r"^[A-Za-z0-9_.-]+(/[A-Za-z0-9_.-]+)*$")
# Exact subpaths permitted for read/write alongside plain basenames.
# Narrow operator-key-management allowlist: membership is an exact string
# match, so no wildcards and no traversal are expressible. Template flows
# (diff/amend/append/pull) still require TARGET_MD_FILES.
MD_ALLOWED_SUBPATHS = frozenset({
".ssh/authorized_keys",
})
def validate_account(account: str) -> str:
"""Reject account values that could escape the cookies/config path."""
@@ -70,6 +78,8 @@ def validate_filename(filename: str, template_only: bool = False) -> str:
"Unknown shared template %r: must be one of %s"
% (filename, sorted(TARGET_MD_FILES)))
return filename
if isinstance(filename, str) and filename in MD_ALLOWED_SUBPATHS:
return filename
if not isinstance(filename, str) or filename in (".", "..") \
or not MD_FILENAME_RE.fullmatch(filename):
raise MDValidationError(