Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Directory name bug #21

Open
paf31 opened this issue May 7, 2017 · 3 comments · Fixed by #29
Open

Directory name bug #21

paf31 opened this issue May 7, 2017 · 3 comments · Fixed by #29
Labels

Comments

@paf31
Copy link
Contributor

paf31 commented May 7, 2017

We construct several directory and file paths using </>. If a package set, package or tag name has path parts in its name such as .., then this allows psc-package to create files outside the project directory. This is obviously a bug, and possibly a security issue, so we should disallow such filenames.

@paf31 paf31 added the bug label May 7, 2017
@hdgarrood
Copy link
Contributor

Interested in taking a stab at this. How about newtypes and smart constructors for each of those three things?

@paf31
Copy link
Contributor Author

paf31 commented May 14, 2017

Yes I think so.

hdgarrood added a commit that referenced this issue May 21, 2017
Part of #21; this does not fully fix #21 as it only addresses package
names.
@paf31 paf31 closed this as completed in #29 May 27, 2017
paf31 pushed a commit that referenced this issue May 27, 2017
Part of #21; this does not fully fix #21 as it only addresses package
names.
@paf31 paf31 reopened this May 27, 2017
@justinwoo
Copy link
Collaborator

Is there anything more to do here, or has this been solved by the PR?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants