diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-10-29 03:40:09 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-10-29 03:40:09 +0900 |
| commit | 274686d10d3386a41f8fb6bc3363269a734afe0e (patch) | |
| tree | 59ce81d5617cf5e1f67b819dab49b83b71d8ff93 /internal/validate/validate.go | |
| parent | 65342d588ff061d2130e6379d86a26be90c908ae (diff) | |
internal/validate: relocate from app
These are free of the dispatcher from internal/app. This change relocates them into their own package.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'internal/validate/validate.go')
| -rw-r--r-- | internal/validate/validate.go | 20 |
1 files changed, 20 insertions, 0 deletions
diff --git a/internal/validate/validate.go b/internal/validate/validate.go new file mode 100644 index 00000000..a4e82753 --- /dev/null +++ b/internal/validate/validate.go @@ -0,0 +1,20 @@ +// Package validate provides functions for validating string values of various types. +package validate + +import ( + "path/filepath" + "strings" +) + +// DeepContainsH returns whether basepath is equivalent to or is the parent of targpath. +// +// This is used for path hiding warning behaviour, the purpose of which is to improve +// user experience and is *not* a security feature and must not be treated as such. +func DeepContainsH(basepath, targpath string) (bool, error) { + const upper = ".." + string(filepath.Separator) + + rel, err := filepath.Rel(basepath, targpath) + return err == nil && + rel != ".." && + !strings.HasPrefix(rel, upper), err +} |
