davsclaus commented on code in PR #27522:
URL: https://github.com/apache/camel/pull/27522#discussion_r4215824113


##########
components/camel-file/src/main/java/org/apache/camel/component/file/FileOperations.java:
##########
@@ -256,11 +257,40 @@ public void releaseRetrievedFileResources(Exchange 
exchange) throws GenericFileO
         // java.io.File
     }
 
+    /**
+     * The jailStartingDirectory check of the producer is lexical (see {@code 
GenericFileProducer.createFileName}), so a
+     * symbolic link inside the starting directory (a link to a file, or a 
directory segment of the name) would redirect
+     * the write outside of it. Only paths that are lexically inside the 
starting directory are checked, so a
+     * tempFileName the route author placed outside of it (such as ../work) 
keeps working.
+     */
+    private void jailToStartingDirectory(File target) {

Review Comment:
   Optional, building on the limit you describe in the PR: with 
`autoCreate=true` the producer calls `buildDirectory` before `storeFile`, so 
for `link/new/x.txt` the directory `new` is created inside the link target 
before this check rejects the write. Calling `jailToStartingDirectory(path)` in 
`buildDirectory` before the directories are created (it already skips paths 
that are lexically outside, so a `../work` temp directory keeps working) would 
stop that, and a test asserting that `elsewhere/new` does not exist after the 
rejected write would cover it.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to