safeRelativeAssetPath function
A reference inside a model is always relative to the model. An absolute path
or a .. segment means the file is reaching outside its directory, which is
worth refusing rather than resolving.
Public because the sources that need it are in another package now, and a second copy of this check is a second chance to get it wrong.
Implementation
String safeRelativeAssetPath(String uri) {
final relative = Uri.decodeComponent(uri);
if (relative.startsWith('/') ||
relative.startsWith(r'\') ||
relative.contains('://') ||
relative.split(RegExp(r'[/\\]')).contains('..')) {
throw ArgumentError(
'Refusing to load "$uri": it escapes the asset directory.',
);
}
return relative;
}