mirror of
https://github.com/flatpak/flatpak.git
synced 2026-10-06 12:59:38 -04:00
handle_remove_local_ref validates the remote name but passes the ref string directly to flatpak_dir_remove_ref without validation. Since the polkit action for this method is modify-repo (allow_active=yes), any active session user can delete arbitrary ostree refs in the system repo without authentication. All legitimate callers of RemoveLocalRef pass standard flatpak refs (app/runtime). Non-standard refs like appstream/, appstream2/, and ostree-metadata are managed through their own dedicated D-Bus methods (DeployAppstream, UpdateRemote, ConfigureRemote) and never go through RemoveLocalRef. Validate the ref with flatpak_decomposed_new_from_ref() to restrict removal to valid flatpak refs.