diff options
Diffstat (limited to 'internal/notify/service.go')
| -rw-r--r-- | internal/notify/service.go | 7 |
1 files changed, 4 insertions, 3 deletions
diff --git a/internal/notify/service.go b/internal/notify/service.go index d46293f..2442127 100644 --- a/internal/notify/service.go +++ b/internal/notify/service.go @@ -14,7 +14,7 @@ package notify import ( "log" "os" - "strings" + "path/filepath" "sync" "time" @@ -52,12 +52,13 @@ func NewService(conn *dbus.Conn, dir string) *Service { } // removeImage unlinks only what the daemon wrote, so a client's own image-path -// is never touched. +// is never touched. A cleaned path must sit directly inside the image +// directory, which also refuses a `..` traversal to a sibling daemon file. func (s *Service) removeImage(path string) { if path == "" { return } - if !strings.HasPrefix(path, ImagesDir(s.dir)+string(os.PathSeparator)) { + if filepath.Dir(filepath.Clean(path)) != ImagesDir(s.dir) { return } os.Remove(path) |
