Commit Graph
3 Commits
Author SHA1 Message Date
Isaac ConnorandClaude Opus 4.8 38a817353b fix: enforce Storage containment before deleting files
The delete action computed $is_ok_path to confirm the requested path sits
below a configured Storage area, but never consulted it, so the check was
dead code and unlink() ran on whatever path was supplied. The path comes
from detaintPathAllowAbsolute($_REQUEST['path']), which deliberately
permits absolute paths, so nothing else constrained the target.

Return with an error when the path is not below a Storage area. Deleting
already requires System Edit, so this is not reachable by a low privilege
user, but the containment check should do what it was written to do.

The adjacent $path_parts assignment is also unused; left in place as it
predates this change.

Refs GHSA-g355-3rf6-f38v.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-19 13:14:12 -04:00
Isaac Connor dea3b741c9 Require path to be a defined storage area. Use detaintPath to prevent Path Traversal. Fixes GHSA-g355-3rf6-f38v 2024-10-21 17:40:01 -04:00
Isaac Connor 7b36027066 add in files actions, with delete 2023-02-22 05:59:16 -05:00