dvAssetPath function

String? dvAssetPath(
  1. String requestPath
)

The file a request path names, relative to the site; null for a path that is no file or would leave the site.

Decoded before it is checked, so %2e%2e is the same two dots here as it is to any proxy in front of this. A backslash, a drive letter and a dot-dot are refused outright rather than resolved.

Implementation

String? dvAssetPath(String requestPath) {
  final String decoded;
  try {
    decoded = Uri.decodeComponent(requestPath);
  } on ArgumentError {
    return null;
  }
  if (decoded.contains(r'\') || decoded.contains('\u0000')) return null;
  final List<String> segments = <String>[];
  for (final String segment in decoded.split('/')) {
    if (segment.isEmpty || segment == '.') continue;
    if (segment == '..' || segment.contains(':')) return null;
    segments.add(segment);
  }
  if (segments.isEmpty) return null;
  return segments.join('/');
}