summaryrefslogtreecommitdiffstats
path: root/src/keymap.h
diff options
context:
space:
mode:
authorDanilo M. <danix@danix.xyz>2026-08-02 17:32:59 +0200
committerDanilo M. <danix@danix.xyz>2026-08-04 12:52:22 +0200
commit18dffc348f722fc79ed336523982541283bc84e1 (patch)
tree975f2de0e891dd988c4c19471cc4620a35926089 /src/keymap.h
parent5f22f80b6b5cef5e768086338ae4b22120f3e67c (diff)
downloadqtmaildir-18dffc348f722fc79ed336523982541283bc84e1.tar.gz
qtmaildir-18dffc348f722fc79ed336523982541283bc84e1.zip
fix: make attachment path-containment guard separator-aware
Attachment::saveTo()'s escape guard compared paths with a bare QString::startsWith(), which is not a path-boundary test: "/tmp/safe-evil" textually starts with "/tmp/safe", so a sibling directory whose name merely extends the target's name would incorrectly pass as contained within it. Extract the check into Attachment::isPathInsideDirectory(), comparing QDir::cleanPath()'d absolute paths and requiring an exact match or a prefix ending at a '/' boundary. Not exploitable today since safeFilename() always reduces the name to a bare basename before saveTo() builds the target, so the guard is unreachable via saveTo()'s public interface; comments on both now say so plainly instead of implying it is currently load-bearing. Add pathInsideDirectoryRejectsSiblingPrefix, testing the guard directly (independent of safeFilename(), which would mask a broken guard by never producing an escaping path), and safeFilenameStripsPathComponents, testing the sanitiser that actually stops traversal today.
Diffstat (limited to 'src/keymap.h')
0 files changed, 0 insertions, 0 deletions