Files
Alberto Schiabel f67d565743 refactor(python): consolidate path construction from untrusted input (#4144)
This PR:

- centralizes filesystem path construction for API-provided slugs and
filenames in `composio.utils.safe_path`
- rejects traversal, Windows-invalid names, invalid Unicode, and
overlong encoded filenames before creating directories or writing files
- normalizes trusted roots consistently and routes both Python download
paths through the shared helpers
- adds a fail-closed AST guard for new dynamic path construction,
including direct `Path(...)` calls
- isolates provider initialization from the real home directory and
makes the home-write guard report changes without deleting them
- removes the obsolete download filename wrapper

## Verification

- `pytest -q`: 1,248 passed, 47 skipped
- repository-configured Ruff checks and formatting passed for every
changed Python file
- targeted mypy checks passed for the changed helpers and tests
2026-08-18 13:07:07 +02:00

23 lines
648 B
Python

"""Behavioral tests for the real-home write guard."""
from types import SimpleNamespace
import pytest
from tests.conftest import guard_real_home_directory
def test_real_home_guard_reports_without_deleting_new_directory(tmp_path):
baseline = {"path": tmp_path, "entries": set()}
request = SimpleNamespace(node=SimpleNamespace(nodeid="test_external_write"))
guard = guard_real_home_directory.__wrapped__(request, baseline)
next(guard)
unrelated = tmp_path / "unrelated-empty-directory"
unrelated.mkdir()
with pytest.raises(pytest.fail.Exception, match="created"):
next(guard)
assert unrelated.is_dir()