aboutsummaryrefslogtreecommitdiffhomepage
path: root/internal/validate/validate.go
diff options
context:
space:
mode:
Diffstat (limited to 'internal/validate/validate.go')
-rw-r--r--internal/validate/validate.go20
1 files changed, 20 insertions, 0 deletions
diff --git a/internal/validate/validate.go b/internal/validate/validate.go
new file mode 100644
index 00000000..a4e82753
--- /dev/null
+++ b/internal/validate/validate.go
@@ -0,0 +1,20 @@
+// Package validate provides functions for validating string values of various types.
+package validate
+
+import (
+ "path/filepath"
+ "strings"
+)
+
+// DeepContainsH returns whether basepath is equivalent to or is the parent of targpath.
+//
+// This is used for path hiding warning behaviour, the purpose of which is to improve
+// user experience and is *not* a security feature and must not be treated as such.
+func DeepContainsH(basepath, targpath string) (bool, error) {
+ const upper = ".." + string(filepath.Separator)
+
+ rel, err := filepath.Rel(basepath, targpath)
+ return err == nil &&
+ rel != ".." &&
+ !strings.HasPrefix(rel, upper), err
+}