Add a safe_relpath util function for ensuring a path does not reference an absolute or parent directory

This commit is contained in:
Nate Coraor
2016-02-24 16:39:15 -05:00
parent 2656f11b51
commit b14e35f48b
+17 -1
View File
@@ -23,7 +23,7 @@ import time
import tempfile
import threading
from os.path import relpath
from os.path import relpath, normpath
from hashlib import md5
from six import binary_type
@@ -1350,6 +1350,22 @@ def parse_int(value, min_val=None, max_val=None, default=None, allow_none=False)
raise
def safe_relpath(path):
"""
Given what we expect to be a relative path, determine whether the path
would exist inside the current directory.
:type path: string
:param path: a path to check
:rtype: bool
:returns: ``True`` if path is relative and does not reference a path
in a parent directory, ``False`` otherwise.
"""
if path.startswith(os.sep) or normpath(path).startswith(os.pardir):
return False
return True
class ExecutionTimer(object):
def __init__(self):