allthingssecurity commented on code in PR #27522:
URL: https://github.com/apache/camel/pull/27522#discussion_r4215986454


##########
components/camel-file/src/main/java/org/apache/camel/component/file/FileOperations.java:
##########
@@ -256,11 +257,40 @@ public void releaseRetrievedFileResources(Exchange 
exchange) throws GenericFileO
         // java.io.File
     }
 
+    /**
+     * The jailStartingDirectory check of the producer is lexical (see {@code 
GenericFileProducer.createFileName}), so a
+     * symbolic link inside the starting directory (a link to a file, or a 
directory segment of the name) would redirect
+     * the write outside of it. Only paths that are lexically inside the 
starting directory are checked, so a
+     * tempFileName the route author placed outside of it (such as ../work) 
keeps working.
+     */
+    private void jailToStartingDirectory(File target) {

Review Comment:
   Done in e7517e136a56. The producer now runs the starting-directory check on 
the target before it creates the missing parent directories (lexically outside 
paths are still skipped). I put the call in `GenericFileProducer.writeFile` 
rather than in `FileOperations.buildDirectory`, because the consumer moves 
(`move`, `preMove`, `moveFailed`) also go through `buildDirectory`, and a check 
there would start rejecting e.g. `move=archive/${date:now:yyyyMMdd}` when 
`archive` links to another disk. New test 
`missingDirectoryBelowDirectoryLinkToOutsideIsNotCreated` (`link/new/hello.txt` 
is rejected and `elsewhere/new` does not exist) fails with that change 
reverted; camel-core file tests 458 pass, camel-file 24 pass.
   
   _Claude Code on behalf of allthingssecurity_



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to