From b14e35f48ba86d836ab78dad56bace573b6836f1 Mon Sep 17 00:00:00 2001 From: Nate Coraor Date: Wed, 24 Feb 2016 16:39:15 -0500 Subject: [PATCH] Add a safe_relpath util function for ensuring a path does not reference an absolute or parent directory --- lib/galaxy/util/__init__.py | 18 +++++++++++++++++- 1 file changed, 17 insertions(+), 1 deletion(-) diff --git a/lib/galaxy/util/__init__.py b/lib/galaxy/util/__init__.py index 6278e64e95c..f05a021ea85 100644 --- a/lib/galaxy/util/__init__.py +++ b/lib/galaxy/util/__init__.py @@ -23,7 +23,7 @@ import time import tempfile import threading -from os.path import relpath +from os.path import relpath, normpath from hashlib import md5 from six import binary_type @@ -1350,6 +1350,22 @@ def parse_int(value, min_val=None, max_val=None, default=None, allow_none=False) raise +def safe_relpath(path): + """ + Given what we expect to be a relative path, determine whether the path + would exist inside the current directory. + + :type path: string + :param path: a path to check + :rtype: bool + :returns: ``True`` if path is relative and does not reference a path + in a parent directory, ``False`` otherwise. + """ + if path.startswith(os.sep) or normpath(path).startswith(os.pardir): + return False + return True + + class ExecutionTimer(object): def __init__(self):