fix(auth): make diagnostics match runtime safety

This commit is contained in:
2026-08-17 11:23:52 +02:00
parent f0ae680671
commit 7cfbee36fa
14 changed files with 619 additions and 99 deletions
+17 -3
View File
@@ -399,13 +399,27 @@ function privateDirectory(path: string): void {
}
}
function validateSessionRootSyntax(root: string): void {
if (process.platform === "win32" || typeof root !== "string" || root.length === 0
|| root.includes("\0") || /\p{Cc}/u.test(root) || !isAbsolute(root) || normalize(root) !== root) throw invalid();
}
/** Side-effect-free POSIX validator shared by runtime storage and static diagnostics. */
export function validateAuthSessionRoot(root: string): void {
try {
validateSessionRootSyntax(root);
directoryIdentity(root);
} catch {
throw invalid();
}
}
function storageDirectories(root: string): StorageDirectories {
// Native Windows calls must dispatch to the tht DACL-capable bridge before reaching this
// POSIX-only helper. Keep this guard so an un-routed caller cannot fall back to chmod.
if (process.platform === "win32") throw invalid();
if (typeof root !== "string" || root.length === 0 || root.includes("\0")
|| !isAbsolute(root) || normalize(root) !== root) throw invalid();
validateSessionRootSyntax(root);
privateDirectory(root);
validateAuthSessionRoot(root);
const sessions = join(root, "sessions");
const oidc = join(root, "oidc");
privateDirectory(sessions);