docs: clarify project {file:} rejects paths that escape the project root

In-root absolute paths are intentionally allowed; only references that leave the root (absolute paths outside it, ../ traversal, symlinks) are rejected. Fix the docs wording and add a regression test for the in-root absolute case.
This commit is contained in:
Mark IJbema
2026-07-06 10:03:15 +02:00
parent 47a40fe7f7
commit faa2bae104
3 changed files with 21 additions and 2 deletions
@@ -47,6 +47,25 @@ test("allows untrusted file references that stay inside the scope root", async (
}
})
test("allows untrusted absolute file references that resolve inside the scope root", async () => {
const root = await fs.realpath(await fs.mkdtemp(path.join(os.tmpdir(), "kilo-config-variable-abs-inside-")))
const file = path.join(root, "value")
await fs.writeFile(file, "allowed")
try {
// An absolute path is fine as long as it stays inside the root; only escapes are rejected.
expect(
await ConfigVariable.substitute({
...source,
dir: root,
text: `{file:${file}}`,
fileScope: { root, source: path.join(root, "kilo.json") },
}),
).toBe("allowed")
} finally {
await fs.rm(root, { recursive: true, force: true })
}
})
test("rejects environment references in untrusted (project) config", async () => {
await expect(
ConfigVariable.substitute({ ...source, text: "value={env:SAFE_VALUE}", env: { SAFE_VALUE: "allowed" } }),