fix(storage): harden portable path diagnostics
This commit is contained in:
@@ -39,7 +39,11 @@ def resolve_workspace_paths(
|
||||
Relative roots are sandboxed to the logical workspace. Absolute roots are a
|
||||
compatibility bridge for existing installations and are never rewritten.
|
||||
"""
|
||||
workspace = (data_root / "workspaces" / config_path.stem).resolve()
|
||||
canonical_data_root = data_root.resolve()
|
||||
workspaces_root = canonical_data_root / "workspaces"
|
||||
workspace = (workspaces_root / config_path.stem).resolve()
|
||||
if not workspace.is_relative_to(workspaces_root):
|
||||
raise ConfigError("workspace resolves outside workspaces root")
|
||||
roots = cfg.roots
|
||||
return ResolvedPaths(
|
||||
workspace=workspace,
|
||||
|
||||
Reference in New Issue
Block a user