fix(work): import hashlib and wire heal subparser into main CLI
This commit is contained in:
@@ -48,6 +48,14 @@ MD_ACCOUNT_RE = re.compile(r"^[A-Za-z0-9][A-Za-z0-9_-]{0,31}$")
|
||||
MD_FILENAME_RE = re.compile(r"^[A-Za-z0-9_.-]{1,128}$")
|
||||
MD_SUBPATH_RE = re.compile(r"^[A-Za-z0-9_.-]+(/[A-Za-z0-9_.-]+)*$")
|
||||
|
||||
# Exact subpaths permitted for read/write alongside plain basenames.
|
||||
# Narrow operator-key-management allowlist: membership is an exact string
|
||||
# match, so no wildcards and no traversal are expressible. Template flows
|
||||
# (diff/amend/append/pull) still require TARGET_MD_FILES.
|
||||
MD_ALLOWED_SUBPATHS = frozenset({
|
||||
".ssh/authorized_keys",
|
||||
})
|
||||
|
||||
|
||||
def validate_account(account: str) -> str:
|
||||
"""Reject account values that could escape the cookies/config path."""
|
||||
@@ -70,6 +78,8 @@ def validate_filename(filename: str, template_only: bool = False) -> str:
|
||||
"Unknown shared template %r: must be one of %s"
|
||||
% (filename, sorted(TARGET_MD_FILES)))
|
||||
return filename
|
||||
if isinstance(filename, str) and filename in MD_ALLOWED_SUBPATHS:
|
||||
return filename
|
||||
if not isinstance(filename, str) or filename in (".", "..") \
|
||||
or not MD_FILENAME_RE.fullmatch(filename):
|
||||
raise MDValidationError(
|
||||
|
||||
Reference in New Issue
Block a user