diff options
| author | Ralph Amissah <ralph.amissah@gmail.com> | 2026-09-20 23:37:45 -0400 |
|---|---|---|
| committer | Ralph Amissah <ralph.amissah@gmail.com> | 2026-09-22 12:02:31 -0400 |
| commit | 0e60ccbeeeb6848d571c4caa78850022a9487288 (patch) | |
| tree | 37fd65af6e71f6dad4527f761336316cca641cf7 /org/out_sqlite.org | |
| parent | markup: keep a utf-8 bom out of the yaml header (diff) | |
ocda db: before writing check carried file names
bugfix: content image names are now checked in a pass of their own,
before anything is created or written, and one bad name refuses every
image in the artefact rather than skipping the one, which is what the
zip reader does with a zip. The write then re-checks containment.
(prior to this an image name read out of a .ocda.db was written without
checks, and such a database can be fetched over https. A name could
climb with "..", and being handed to chainPath an absolute name dropped
everything before it, so "/x" did not land under the image directory at
all. The zip reader has guarded against this since it was written; the
database reader did not).
carried_names.d holds both rules: a bare filename, as an image is
carried, and a relative path, for the markup and conf a database is to
carry.
(assisted by Claude-Code)
Diffstat (limited to 'org/out_sqlite.org')
0 files changed, 0 insertions, 0 deletions
