Commit Graph

3 Commits

Author SHA1 Message Date
Alberto Schiabel f67d565743 refactor(python): consolidate path construction from untrusted input (#4144)
This PR:

- centralizes filesystem path construction for API-provided slugs and
filenames in `composio.utils.safe_path`
- rejects traversal, Windows-invalid names, invalid Unicode, and
overlong encoded filenames before creating directories or writing files
- normalizes trusted roots consistently and routes both Python download
paths through the shared helpers
- adds a fail-closed AST guard for new dynamic path construction,
including direct `Path(...)` calls
- isolates provider initialization from the real home directory and
makes the home-write guard report changes without deleting them
- removes the obsolete download filename wrapper

## Verification

- `pytest -q`: 1,248 passed, 47 skipped
- repository-configured Ruff checks and formatting passed for every
changed Python file
- targeted mypy checks passed for the changed helpers and tests
2026-08-18 13:07:07 +02:00
jkomyno 64fbc4ee03 fix(py): preserve nested provider argument presence 2026-08-10 22:14:21 +02:00
jkomyno 5bb1e20518 fix(py): preserve serialized provider arguments
Co-authored-by: Aditya Chawla <aditya17.mitmpl2023@learner.manipal.edu>
2026-08-10 20:02:23 +02:00