From 1d63a0127065a41c04fdfe7049ec6392a5b5ba62 Mon Sep 17 00:00:00 2001 From: John Chilton Date: Wed, 24 Sep 2014 15:21:44 -0400 Subject: [PATCH] Allow remotely executed tools to write version files to the temp directory. Like with discovered datasets - such use of this directory should be phased out in favor of the job's working directory of a job relative to it. --- lib/galaxy/webapps/galaxy/api/job_files.py | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/lib/galaxy/webapps/galaxy/api/job_files.py b/lib/galaxy/webapps/galaxy/api/job_files.py index 0b2ce5391db..9fa3695546b 100644 --- a/lib/galaxy/webapps/galaxy/api/job_files.py +++ b/lib/galaxy/webapps/galaxy/api/job_files.py @@ -118,9 +118,16 @@ class JobFilesAPIController( BaseAPIController ): https://gist.github.com/jmchilton/9103619.) """ in_work_dir = self.__in_working_directory( job, path, trans.app ) - if not in_work_dir and not self.__is_output_dataset_path( job, path ): + allow_temp_dir_file = self.__is_allowed_temp_dir_file( trans.app, job, path ) + if not in_work_dir and not allow_temp_dir_file and not self.__is_output_dataset_path( job, path ): raise exceptions.ItemAccessibilityException("Job is not authorized to write to supplied path.") + def __is_allowed_temp_dir_file( self, app, job, path ): + # grrr.. need to get away from new_file_path - these should be written + # to job working directory like metadata files. + in_temp_dir = util.in_directory( path, app.config.new_file_path ) + return in_temp_dir and os.path.split( path )[ -1 ].startswith( "GALAXY_VERSION_") + def __is_output_dataset_path( self, job, path ): """ Check if is an output path for this job or a file in the an output's extra files path.