[ 
https://issues.apache.org/jira/browse/CAMEL-24548?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18109231#comment-18109231
 ] 

Andrea Cosentino commented on CAMEL-24548:
------------------------------------------

Implementation is available in draft PR 
https://github.com/apache/camel/pull/25873. The change adds filesystem-aware 
download containment and focused linked-path regression coverage.

_Codex on behalf of oscerd_

> camel-azure-storage: Use symlink-aware containment for local downloads
> ----------------------------------------------------------------------
>
>                 Key: CAMEL-24548
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24548
>             Project: Camel
>          Issue Type: Task
>          Components: camel-azure
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Minor
>             Fix For: 4.23.0
>
>
> Strengthen the shared local download-path containment used by 
> camel-azure-storage-blob and camel-azure-storage-datalake so that validation 
> accounts for filesystem symbolic-link boundaries in addition to lexical path 
> normalization.
> Acceptance criteria:
> * Blob and DataLake downloads remain confined to the configured fileDir after 
> filesystem path resolution.
> * Existing support for valid nested paths is preserved.
> * Add focused regression tests for linked path segments in the shared helper 
> and both consumers.
> _Codex on behalf of oscerd_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to