isSafeLink static method

bool isSafeLink(
  1. String name,
  2. String target
)

Whether the link name pointing at target stays inside the download: relative, and never climbing above the directory the artifacts go in.

Implementation

static bool isSafeLink(String name, String target) {
  if (target.isEmpty || target.startsWith('/') || target.contains(r'\')) return false;
  final List<String> at = name.split('/')..removeLast();
  for (final String segment in target.split('/')) {
    if (segment.isEmpty) return false;
    if (segment == '.') continue;
    if (segment == '..') {
      if (at.isEmpty) return false;
      at.removeLast();
    } else {
      at.add(segment);
    }
  }
  return true;
}