refactor(workbench): share safe source path validation - #396
Conversation
|
@codex review |
|
Codex Review: Didn't find any major issues. Keep them coming! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
zcrab-oai
left a comment
There was a problem hiding this comment.
Looks good. Reuses the identical safe source-path validator without weakening traversal, symlink, or Windows path protections.
Summary
Use one implementation for validating finding source paths.
Changes
Testing
bun test tests-ts/plugin-report-limits.test.ts tests-ts/scan-recovery.test.ts --timeout 30000— passed.python3 -I -Bimport and path-boundary smoke test — confirmed both modules share the same helper, safe paths remain accepted, and traversal/backslash paths remain rejected.pnpm run types— passed.git diff --check— passed.Risk and rollout
The shared helper is byte-for-byte equivalent to the removed implementation. Existing repository containment, path traversal, and source-excerpt protections remain unchanged.
Public disclosure review