mirror of
https://github.com/ComposioHQ/composio.git
synced 2026-09-22 11:46:35 +08:00
27ed0c9bd6
## Summary Security-hardening for automatic file upload in `@composio/core` (patch release per changeset). ### Changes - **Default denylist** for local paths before auto-upload / `files.upload`: blocks common credential directories (e.g. `.ssh`, `.aws`) and credential-like filenames (e.g. `.env`, default SSH private keys). Resolves symlinks when the path exists. - **Config:** `sensitiveFileUploadProtection`, `fileUploadPathDenySegments` on `Composio`. - **`beforeFileUpload`** hook (e.g. with `composio.tools.get` / `tools.execute`): rewrite path, return `false` to abort, or throw. - **Errors:** `ComposioSensitiveFilePathBlockedError`, `ComposioFileUploadAbortedError`; file modifier errors exported from `@composio/core` errors entry. - **Changeset:** patch bump for `@composio/core`. ### Notes - URLs and `File` blobs are not subject to the path denylist (unchanged). - Opt out of path checks only if required: `sensitiveFileUploadProtection: false`. ### Tests - `pnpm test` in `ts/packages/core` (799 tests) passed locally before commit. Made with [Cursor](https://cursor.com)
2.3 KiB
2.3 KiB