Skip to content

Fix/remove validate path false - #91

Merged
HC-ONLINE merged 6 commits into
mainfrom
fix/remove-validate-path-false
Sep 30, 2026
Merged

HC-ONLINE merged 6 commits into
mainfrom
fix/remove-validate-path-false

Conversation

@HC-ONLINE

Copy link
Copy Markdown
Owner

Description

Replace the validate_path=False bypass in BaseService._export_result() with an explicit allowed_base parameter.

The previous implementation allowed callers to skip path validation entirely when they had previously validated the path against a different security boundary. This was used by ConfigService, which validates configuration exports against get_config_base_dir() rather than the normal export directory.

This change preserves that distinction while making validation mandatory:

  • allowed_base=None preserves the existing export-base behavior.
  • Callers with a different security boundary can provide an explicit allowed_base.
  • resolve_and_validate_path() is now always executed before the filesystem is accessed.
  • ConfigService passes its already-selected configuration base explicitly instead of disabling validation.
  • The public exporter API remains unchanged and is intentionally not sandboxed.

Additional regression tests verify:

  • Path traversal is rejected at the service layer.
  • Absolute paths outside the allowed base are rejected.
  • validate_path=False is no longer accepted.
  • The explicitly supplied allowed_base is actually used.
  • ConfigService can export within its configuration directory while remaining outside the normal export sandbox.
  • Public exporters continue to support arbitrary caller-provided paths and are not accidentally sandboxed.
  • Stream exports remain unaffected.

The purpose of this PR is also to verify the resulting CodeQL analysis. No CodeQL suppressions, custom models, or exporter-level security changes are introduced in this PR.

Related Issue

Fixes # (issue number)

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)

Testing

Local validation completed:

  • pytest -m "not integration" — 1413 passed, 2 skipped, 80 deselected
  • ruff check . — passed
  • ruff format --check . — passed
  • pyright — 0 errors, 0 warnings, 0 informations
  • git diff --check — passed

Local tests were executed on Python 3.12.

CodeQL is expected to run through GitHub Actions. The result will be used to determine whether the existing CodeQL findings are correctly resolved by the service-layer change or whether additional CodeQL modeling is required.

@HC-ONLINE
HC-ONLINE merged commit 85cc273 into main Sep 30, 2026
6 checks passed
@HC-ONLINE
HC-ONLINE deleted the fix/remove-validate-path-false branch October 1, 2026 16:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant