Commit Graph
5 Commits
Author SHA1 Message Date
google-labs-jules[bot]andAEmotionStudio 6de50104f1 Fix path traversal vulnerability in file output validation
Co-authored-by: AEmotionStudio <163354043+AEmotionStudio@users.noreply.github.com>
2026-02-09 16:12:04 +00:00
google-labs-jules[bot] 523fe68f6b Address PR review feedback: validation for non-existent dirs
- Updated `shared/path_utils.py`: `validate_path_is_safe` now walks up the directory tree to verify the first existing ancestor is not a symlink, preventing bypasses via non-existent intermediate directories.
- Updated `tests/test_symlink_attack.py`: Added regression test `test_non_existent_directory_symlink_bypass`.
2026-01-23 02:38:20 +00:00
google-labs-jules[bot] ad360061d7 Address PR review feedback: robust symlink validation
- Updated `shared/path_utils.py`: `validate_path_is_safe` now checks for symlinks in parent directories by verifying realpath vs abspath mismatch.
- Updated `nodes/video_node.py`: Added `validate_path_is_safe` check to the VHS format path recalculation block to prevent bypass.
- Updated `tests/test_symlink_attack.py`: Added regression tests for parent directory symlinks and VHS format bypass.
2026-01-23 02:05:40 +00:00
google-labs-jules[bot] 0e655a4303 Fix symlink overwrite vulnerability in custom nodes
- Implemented `validate_path_is_safe` in `shared/path_utils.py` to reject writing to symlinks.
- Applied validation in `nodes/video_node.py` and `nodes/image_node.py` before file operations.
- Added regression test `tests/test_symlink_attack.py`.
- Updated sentinel journal with new vulnerability pattern.
2026-01-23 01:37:51 +00:00
AEmotionStudioandClaude Opus 4.5 a208cd482b refactor(phase2): extract shared utilities and reduce node duplication
- Create shared/filename_utils.py for date/time/dimension filename building
- Create shared/path_utils.py for output directory handling
- Create shared/discord/message_builder.py for Discord message construction
- Create shared/discord/cdn_extractor.py for CDN URL extraction
- Refactor image_node.py to use shared utilities (-161 lines, 16.3%)
- Refactor video_node.py to use shared utilities (-361 lines, 23.1%)
- Fix setup_logging missing from logging_config.py
- Fix test imports to use new module paths (nodes.* instead of discord_*_node)
- Total reduction: 522 lines (20.5%), exceeding PRD target of ~200 lines

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-19 23:33:10 -08:00