fix(auth): complete Task 13 deployment review
This commit is contained in:
@@ -572,6 +572,13 @@ func validateVolumeTar(ctx context.Context, member *zip.File) error {
|
||||
return fmt.Errorf("read volume archive: %w", err)
|
||||
}
|
||||
name := strings.TrimSuffix(header.Name, "/")
|
||||
if name == "." {
|
||||
if header.Typeflag != tar.TypeDir {
|
||||
return errors.New("volume archive root marker is not a directory")
|
||||
}
|
||||
continue
|
||||
}
|
||||
name = strings.TrimPrefix(name, "./")
|
||||
if _, err := validateArchiveMemberPath(name); err != nil {
|
||||
return fmt.Errorf("volume archive path is unsafe: %w", err)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user