Skip to content

fix(security): detect Windows drive letters and reserved device names in isArchiveEntryNameSafe (#919) - #950

Merged
ZhuchkaTriplesix merged 1 commit into
devfrom
issue/919-archive-entry-windows-safety
Sep 25, 2026
Merged

ZhuchkaTriplesix merged 1 commit into
devfrom
issue/919-archive-entry-windows-safety

Conversation

@ZhuchkaTriplesix

Copy link
Copy Markdown
Member

Closes #919

Summary of Changes

  • Updated isArchiveEntryNameSafe in lib/core/security/archive_path_guard.dart to:
    • Reject empty entry names.
    • Reject entry names containing null bytes or control characters ([\x00-\x1F\x7F]).
    • Reject entry names containing Windows drive letters ((?:^|[\/\\])[a-zA-Z]:).
    • Reject path segments matching Windows reserved device names and their extensions (CON, PRN, AUX, NUL, COM1-9, LPT1-9).
  • Added comprehensive unit tests in test/core/security/archive_path_guard_test.dart covering drive letters, device names (both root and nested), null bytes, control characters, empty names, and benign file names.

@github-actions github-actions Bot added bug Something isn't working marketplace Extensions marketplace, ExtensionManifest core Core library logic and services labels Sep 25, 2026
@github-actions github-actions Bot added this to the 0.4.18 milestone Sep 25, 2026
@ZhuchkaTriplesix
ZhuchkaTriplesix merged commit 34f07d6 into dev Sep 25, 2026
3 checks passed
@ZhuchkaTriplesix
ZhuchkaTriplesix deleted the issue/919-archive-entry-windows-safety branch September 28, 2026 08:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working core Core library logic and services marketplace Extensions marketplace, ExtensionManifest

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant