diff options
Diffstat (limited to 'internal/validate/validate.go')
| -rw-r--r-- | internal/validate/validate.go | 20 |
1 files changed, 20 insertions, 0 deletions
diff --git a/internal/validate/validate.go b/internal/validate/validate.go new file mode 100644 index 00000000..a4e82753 --- /dev/null +++ b/internal/validate/validate.go @@ -0,0 +1,20 @@ +// Package validate provides functions for validating string values of various types. +package validate + +import ( + "path/filepath" + "strings" +) + +// DeepContainsH returns whether basepath is equivalent to or is the parent of targpath. +// +// This is used for path hiding warning behaviour, the purpose of which is to improve +// user experience and is *not* a security feature and must not be treated as such. +func DeepContainsH(basepath, targpath string) (bool, error) { + const upper = ".." + string(filepath.Separator) + + rel, err := filepath.Rel(basepath, targpath) + return err == nil && + rel != ".." && + !strings.HasPrefix(rel, upper), err +} |
