fix: harden URL-decoded image paths

Co-authored-by: zcqqq <10296164+zcqqq@users.noreply.github.com>
This commit is contained in:
Jim Liu 宝玉
2026-05-27 21:34:59 -05:00
parent 876f01ac19
commit 84cefc2784
6 changed files with 130 additions and 13 deletions
+21 -4
View File
@@ -181,12 +181,29 @@ async function resolveImagePath(imagePath: string, baseDir: string, tempDir: str
return localPath;
}
const decoded = decodeURIComponent(imagePath);
if (path.isAbsolute(decoded)) {
return decoded;
return resolveLocalImagePath(imagePath, baseDir);
}
function resolveLocalImagePath(imagePath: string, baseDir: string): string {
const decoded = safeDecodeImagePath(imagePath);
const resolved = resolveAgainstBaseDir(decoded, baseDir);
if (decoded === imagePath || fs.existsSync(resolved)) {
return resolved;
}
return path.resolve(baseDir, decoded);
return resolveAgainstBaseDir(imagePath, baseDir);
}
function safeDecodeImagePath(imagePath: string): string {
try {
return decodeURIComponent(imagePath);
} catch {
return imagePath;
}
}
function resolveAgainstBaseDir(imagePath: string, baseDir: string): string {
return path.isAbsolute(imagePath) ? imagePath : path.resolve(baseDir, imagePath);
}
function escapeHtml(text: string): string {