fix(storage): harden portable path diagnostics
This commit is contained in:
@@ -57,6 +57,28 @@ def test_path_escape_is_rejected(tmp_path):
|
||||
resolve_workspace_paths(cfg_path, cfg, tmp_path / "data")
|
||||
|
||||
|
||||
def test_workspace_symlink_escape_is_rejected(tmp_path):
|
||||
cfg_path = _write_config(tmp_path / "demo.yaml")
|
||||
cfg = load_config(cfg_path)
|
||||
data_root = tmp_path / "data"
|
||||
(data_root / "workspaces").mkdir(parents=True)
|
||||
(data_root / "workspaces" / "demo").symlink_to(tmp_path / "private", target_is_directory=True)
|
||||
|
||||
with pytest.raises(ConfigError, match="outside workspaces root"):
|
||||
resolve_workspace_paths(cfg_path, cfg, data_root)
|
||||
|
||||
|
||||
def test_nested_root_symlink_escape_is_rejected(tmp_path):
|
||||
cfg_path = _write_config(tmp_path / "demo.yaml")
|
||||
cfg = load_config(cfg_path)
|
||||
workspace = tmp_path / "data/workspaces/demo"
|
||||
workspace.mkdir(parents=True)
|
||||
(workspace / "sessions").symlink_to(tmp_path / "private", target_is_directory=True)
|
||||
|
||||
with pytest.raises(ConfigError, match="outside workspace root"):
|
||||
resolve_workspace_paths(cfg_path, cfg, tmp_path / "data")
|
||||
|
||||
|
||||
def test_data_root_environment_activates_portable_paths(monkeypatch, tmp_path):
|
||||
cfg_path = _write_config(tmp_path / "demo.yaml")
|
||||
monkeypatch.setenv("THT_DATA_ROOT", str(tmp_path / "data"))
|
||||
|
||||
Reference in New Issue
Block a user