fix: harden deploy.sh and export-pdf.sh#96
Open
lukesw55 wants to merge 2 commits into
Open
Conversation
- parse HTML asset refs in Python with path-traversal protection (normpath + containment check; rejects ../, absolute and // refs) - clean temp dirs via EXIT trap on all exit paths - invoke Vercel CLI as array to avoid word-splitting - drop the npm install -g global fallback - extract the deploy URL more robustly
- static server listens on 127.0.0.1 instead of all interfaces - reject path-traversal requests with 403 - close browser and server in try/finally - disable animations for deterministic screenshots
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the issues described in #95.
export-pdf.sh
deploy.sh
npm install -gfallback is goneNo interface changes: same arguments, same flow, same user-facing messages.
scripts/and theplugins/frontend-slides/skills/frontend-slides/scripts/copies are updated in sync.bash -npasses on all four scripts. The containment logic lives in the Python (deploy) and Node (export) helpers and is small enough to review directly in the diff.