Skip to content

fix(config): resolve config paths from CWD in CLI and sandbox them in the API - #102

Merged
HC-ONLINE merged 5 commits into
mainfrom
fix/config-path-cli-api
Oct 5, 2026
Merged

HC-ONLINE merged 5 commits into
mainfrom
fix/config-path-cli-api

Conversation

@HC-ONLINE

Copy link
Copy Markdown
Owner

Summary

Fixes config file path handling across CLI, API and service layers.

Defects fixed

  1. CLI resolved config paths against ~/.ciberwebscan instead of the working directory.
    config load examples/profiles/bugbounty.yaml, config export backup.yaml and --config rel.yaml failed or wrote into the global config base instead of the CWD.
  2. save(None) with an explicit config_path could diverge from the loader and produced a raw IsADirectoryError for directory destinations.
  3. path_policy was compared by identity without normalization: ConfigService(path_policy="config_dir") silently activated the LOCAL branch and escaped the ~/.ciberwebscan sandbox.
  4. docs/API.md documented wrong request contracts (updates, file_path, section) that returned 422 in practice.

Changes

  • ConfigService gains PathPolicy (CONFIG_DIR sandbox for the API, LOCAL CWD-based for the CLI); the constructor normalizes PathPolicy | str via PathPolicy(path_policy) and raises ValueError for unknown values (never a silent fallback to LOCAL).
  • Constructor config_path is normalized once (~, absolute) so loader and save() always target the same file; directory destinations fail with a clear CONFIG_SAVE_ERROR.
  • ~ is expanded before containment in CONFIG_DIR; .yaml/.yml/.json enforced in both policies; empty/null-byte/drive-relative paths rejected.
  • CLI validate_file_path reports normalized absolute paths (missing file exits 2, service failures exit 1).
  • Docs updated: docs/API.md (real path/value/save contracts, response shapes, API path sandbox section), docs/CLI.md and docs/CONFIGURATION.md (CWD path resolution rules).

No changes to utils/path_security.py, the CodeQL model, or API route handlers (they still construct ConfigService() bare).

Tests

New regression suites:

  • tests/unit/services/test_config_path_policy.py — policies, save(None) contract, LOCAL rules, path_policy normalization (enum/strings/invalid values)
  • tests/unit/cli/test_config_cli_paths.py — CWD resolution, ~, exit codes
  • tests/unit/api/routes/test_config_path_policies.py — sandbox, ~, auth, request/response contracts, bare constructor, symlink escape

Validation

  • uv run pytest → 1589 passed, 3 skipped (before the final path_policy normalization commit)
  • uv run pytest tests/unit/services/test_config_path_policy.py tests/unit/api/routes/test_config_path_policies.py → 40 passed, 1 skipped (after it)
  • uv run ruff check . → clean; uv run ruff format --check → clean
  • uv run pyright → 0 errors, 0 warnings
  • uv run pre-commit run --all-files → all hooks pass (prettier reformat of release-please CHANGELOG.md is pre-existing and was reverted to keep the diff scoped)

Notes / limitations

  • Symlink-escape test skips on Windows (requires symlink privileges); runs on Linux CI.
  • Windows drive-relative paths (C:file.yaml) are rejected only under the LOCAL policy.

Comment thread src/ciberwebscan/services/config_service.py Dismissed
@HC-ONLINE
HC-ONLINE merged commit dbc3fd2 into main Oct 5, 2026
6 checks passed
@HC-ONLINE
HC-ONLINE deleted the fix/config-path-cli-api branch October 5, 2026 15:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants