fix: harden URL-decoded image paths

Co-authored-by: zcqqq <10296164+zcqqq@users.noreply.github.com>
This commit is contained in:
Jim Liu 宝玉
2026-05-27 21:34:59 -05:00
parent 876f01ac19
commit 84cefc2784
6 changed files with 130 additions and 13 deletions
+20 -5
View File
@@ -103,11 +103,14 @@ export async function resolveImagePath(
return localPath;
}
const decoded = decodeURIComponent(imagePath);
const resolved = path.isAbsolute(decoded)
? decoded
: path.resolve(baseDir, decoded);
return resolveLocalWithFallback(resolved, logLabel);
const decoded = safeDecodeImagePath(imagePath);
const resolved = resolveAgainstBaseDir(decoded, baseDir);
const resolvedWithFallback = resolveLocalWithFallback(resolved, logLabel);
if (decoded === imagePath || fs.existsSync(resolvedWithFallback)) {
return resolvedWithFallback;
}
return resolveLocalWithFallback(resolveAgainstBaseDir(imagePath, baseDir), logLabel);
}
export async function resolveContentImages(
@@ -155,3 +158,15 @@ function resolveLocalWithFallback(resolved: string, logLabel: string): string {
return resolved;
}
function safeDecodeImagePath(imagePath: string): string {
try {
return decodeURIComponent(imagePath);
} catch {
return imagePath;
}
}
function resolveAgainstBaseDir(imagePath: string, baseDir: string): string {
return path.isAbsolute(imagePath) ? imagePath : path.resolve(baseDir, imagePath);
}