module

Cri::PathSecurity

Canonicalizes filesystem paths before authorization and I/O. Lexical prefix checks are insufficient because a path inside a trusted directory can be a symlink to an object outside it.

Class methods

allowed?(path : String, roots : Array(String), create : Bool = false) : Bool
Source
resolve_existing(path : String, base : String | Nil = nil) : String | Nil
Source
resolve_for_authorization(path : String, base : String | Nil = nil) : String | Nil

Permission checks may run before a file is created. Preserve the normalized lexical path for a missing target, but canonicalize every existing target so an existing symlink cannot pass by spelling alone.

Source
resolve_for_create(path : String, base : String | Nil = nil) : String | Nil

Resolves a path that may not exist yet by canonicalizing its nearest existing parent. If the final component already exists, realpath follows it so callers can still enforce the final target's boundary.

Source
within?(path : String, root : String, create : Bool = false) : Bool
Source