From fed32bce5607b98faa121e94f3a41806185c7299 Mon Sep 17 00:00:00 2001 From: martyanov-av Date: Tue, 19 Nov 2024 12:46:17 +0300 Subject: [PATCH] fix: generic include should be inside root --- src/services/includers/batteries/generic.ts | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/src/services/includers/batteries/generic.ts b/src/services/includers/batteries/generic.ts index ece250e1..84fae9c6 100644 --- a/src/services/includers/batteries/generic.ts +++ b/src/services/includers/batteries/generic.ts @@ -4,6 +4,8 @@ import {dirname, join, parse} from 'path'; import {updateWith} from 'lodash'; import {dump} from 'js-yaml'; +import {getRealPath} from '@diplodoc/transform/lib/utilsFS'; + import {glob} from '../../../utils/glob'; import {IncluderFunctionParams} from '../../../models'; @@ -66,7 +68,14 @@ async function includerFunction(params: IncluderFunctionParams) { cache, })); - const writePath = join(writeBasePath, tocDirPath, item.include.path); + const writePath = getRealPath(join(writeBasePath, tocDirPath, item.include.path)); + + if (!writePath.startsWith(writeBasePath)) { + throw new GenericIncluderError( + `Expected the include path to be located inside project root, got: ${writePath}`, + writePath, + ); + } await mkdir(writePath, {recursive: true});