Skip to content

[codex] Constrain registry template paths#132

Open
zunihb wants to merge 1 commit intoln-dev7:masterfrom
zunihb:codex/registry-path-hardening
Open

[codex] Constrain registry template paths#132
zunihb wants to merge 1 commit intoln-dev7:masterfrom
zunihb:codex/registry-path-hardening

Conversation

@zunihb
Copy link
Copy Markdown

@zunihb zunihb commented May 4, 2026

Summary

  • resolve registry file paths against the templates root and reject path traversal
  • make add-content-to-registry import-safe by moving execution into main()
  • add a node:test regression for trusted-prefix traversal attempts

Verification

  • node --test scripts/add-content-to-registry.test.js

@vercel
Copy link
Copy Markdown
Contributor

vercel Bot commented May 4, 2026

@zunihb is attempting to deploy a commit to the ln-dev Team on Vercel.

A member of the Team first needs to authorize it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant