Repository navigation
Conversation
The guard added in #47 still accepted reserved DOS device names such as C:\media\NUL, nul.txt, NUL .txt, COM1, LPT¹ or CONOUT$, which Win32 opens as devices instead of files, and the \??\ prefix, which hands paths such as \??\UNC\host\share to the NT object manager unparsed. Reject both in isWindowsNetworkPath and its Rust twin, so every assertLocalMediaPath caller and the Tauri asset scope guard are covered. Names are matched in every path component, in any case and ignoring an extension or trailing spaces; COM0/LPT0 are rejected conservatively. POSIX paths are unchanged. Signed-off-by: Hao0321 <126182090+Hao0321@users.noreply.github.com> Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YQbUWKu73ka7dZ58vWVzgY
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
#47 made the Windows media-path guard reject UNC paths,
\\.\paths and\\?\device paths. It still accepted two other forms:C:\media\NUL,nul.txt,NUL .txt,CON,AUX,PRN,COM1–COM9,LPT1–LPT9, the superscript formsCOM¹²³andLPT¹²³,CONIN$andCONOUT$. Win32 opens a device for these instead of a file. Matching ignores letter case, extensions, trailing spaces, and:(as inC:NUL).\??\, for example\??\UNC\host\share\x. It hands the path to the object manager without normal parsing, so it can still reach a network share.Both classifiers now reject these on Windows:
isWindowsNetworkPathinsrc/shared/localMediaPath.tsis_windows_network_pathinsrc-tauri/src/main.rs, used byallow_pathBoth stay behind their existing platform gates (
platform === "win32"andcfg!(windows)), so nothing changes on macOS or Linux, whereNULis an ordinary file name.Some cases are rejected deliberately even though they go beyond the minimum; each is explained in a code comment:
updateCache.tscheck already works this way.COM0andLPT0are rejected.\\?\C:\media\NULis rejected.The error message keeps its prefix and now says to copy the file under an ordinary file name.
User journey and platform
Windows only: importing, previewing or analysing media whose path uses a device name or
\??\is refused before ffprobe or the asset protocol touches it. App-generated cache paths and IDs cannot contain these names.Validation
npm run typecheck,npm run build: passed.npm test: 279 files passed, 1 skipped; 2212 tests passed, 5 skipped.npm run source:scanandnpm run source:verify:self-test: GREEN.npx tsx scripts/architecture-check.ts: ALLOW.npm run test:journeywith FFmpeg 6.1.1: GREEN.null.mp4,COM10.mp4,clip.nul.mp4andnul-cut\clip.mp4.inspectMedia,analyzeSceneCuts,probeMedia,analyzeAutomaticCaptionTranscriptandresolveMediaPath.cargo build --locked --manifest-path src-tauri/Cargo.toml --features community-desktop,tauri/custom-protocolpassed. CI's own command,cargo test … windows_network_and_device_paths_are_not_local_media, passed.Security and provenance
No new dependencies, network access, process execution, file writes, permissions, media, fonts or models. No secrets or private footage.
Not covered here, as follow-ups:
src/application/updateCache.tsandscripts/lib/editkin-mcp-generation-contract.mjshave their own, narrower reserved-name checks.DCO
The commit has a
Signed-off-by:trailer.🤖 Generated with Claude Code
https://claude.ai/code/session_01YQbUWKu73ka7dZ58vWVzgY
Generated by Claude Code