dvAssetPath function
The file a request path names, relative to the site; null for a path that is no file or would leave the site.
Decoded before it is checked, so %2e%2e is the same two dots here as it
is to any proxy in front of this. A backslash, a drive letter and a
dot-dot are refused outright rather than resolved.
Implementation
String? dvAssetPath(String requestPath) {
final String decoded;
try {
decoded = Uri.decodeComponent(requestPath);
} on ArgumentError {
return null;
}
if (decoded.contains(r'\') || decoded.contains('\u0000')) return null;
final List<String> segments = <String>[];
for (final String segment in decoded.split('/')) {
if (segment.isEmpty || segment == '.') continue;
if (segment == '..' || segment.contains(':')) return null;
segments.add(segment);
}
if (segments.isEmpty) return null;
return segments.join('/');
}