storage: keep recursive downloads inside the destination folder - #920
Conversation
An object such as "public/../file" is a valid in-bucket path, but once the "public/" prefix is stripped by a recursive download it was written one level above the destination. Check the final local path instead of the object key, and skip the objects that would leave the destination. AI-assisted: true Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
AI-assisted: true Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Note on The check here is lexical (the final local path must stay under the destination), which is enough for the reported case. Happy to do it as a follow-up if we think the stricter behaviour is worth it. |
…li-path-traversal-unsanitized-object-names-upon-recursive-bucket-download-ei0162 # Conflicts: # CHANGELOG.md
quentinalbertone
left a comment
There was a problem hiding this comment.
you should delete IsTraversalPath this fonctoin doesn't work and it will confuse us in the future why two check: one on the key (which doesn't work every time) the other on on the write path
…li-path-traversal-unsanitized-object-names-upon-recursive-bucket-download-ei0162 # Conflicts: # CHANGELOG.md
The check on the local path the object is written to covers every case the key check did, and the key check missed some. Keeping both was confusing. AI-assisted: true Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
@quentinalbertone agreed, |
Description
exo storage download -rcould still write outside of the destination folder: an object namedpublic/../fileis a valid in-bucket path, so it passed the check added in #823, but once thepublic/prefix is stripped it landed one level above the destination.[sc-175532]
Checklist
(For exoscale contributors)
CHANGELOG.md)Testing
Unit tests, plus a new e2e scenario (
storage_download_path_traversal.txtar) run against a real bucket.Note
AI assistance: code, tests, PR description.
🤖 Generated with Claude Code