mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-01 21:31:33 +00:00
* refactor(plugin-sdk): narrow wildcard barrels to explicit used exports * refactor(tools): delete dead tool-planning module exposed by barrel narrowing * fix(plugin-sdk): restore deprecation tag on OpenClawSchemaType alias * test(agents): drop test for deleted runtime proxy module * refactor(tools): trim descriptor types to cache consumers * refactor(deadcode): harvest exports orphaned by barrel narrowing * refactor(deadcode): harvest exports orphaned by barrel narrowing (rest) * fix(agents): restore sdk imports and test markers via public predicate * fix(plugin-sdk): named type re-exports in plugin-entry; trim types barrel precisely * chore(plugin-sdk): account unmasked deprecated provider types in budgets * fix(plugins): name star-only type rows for dts bundling * fix(plugins): restore host-hook surface; unexport internal api compositions * fix(plugins): named type imports for api composition; restore needed source exports * fix(plugins): knip-visible type imports for registry surfaces * test: adapt tests to privatized media and command internals * fix(qa-lab): re-export snapshot conversation type * style: format sessions sdk imports * fix(plugins): restore smoke entry export; pin budgets to exact actuals * fix(plugins): canonical smoke-entry import; drop orphaned root shims * fix(plugins): allowlist manifest probe, repoint qa web import, drop dead browser barrels * fix(plugin-sdk): pin codex auth marker and scaffold provider type * fix(qa-lab): keep web-facing model-selection shim within boundary rules * fix(plugin-sdk): preserve merged contracts through narrowed barrels * chore(plugin-sdk): pin post-rebase surface budgets
32 lines
1.1 KiB
TypeScript
32 lines
1.1 KiB
TypeScript
import { root as fsRoot, type OpenResult } from "../infra/fs-safe.js";
|
|
|
|
/** Safely open a path beneath a trusted root while rejecting hardlinks and unsafe symlinks by default. */
|
|
export async function openFileWithinRoot(params: {
|
|
rootDir: string;
|
|
relativePath: string;
|
|
rejectHardlinks?: boolean;
|
|
nonBlockingRead?: boolean;
|
|
allowSymlinkTargetWithinRoot?: boolean;
|
|
}): Promise<OpenResult> {
|
|
const root = await fsRoot(params.rootDir);
|
|
return await root.open(params.relativePath, {
|
|
hardlinks: params.rejectHardlinks === false ? "allow" : "reject",
|
|
nonBlockingRead: params.nonBlockingRead,
|
|
symlinks: params.allowSymlinkTargetWithinRoot === true ? "follow-within-root" : "reject",
|
|
});
|
|
}
|
|
|
|
/** Copy a source file into a path beneath a trusted root using fs-safe root policy. */
|
|
export async function writeFileFromPathWithinRoot(params: {
|
|
rootDir: string;
|
|
relativePath: string;
|
|
sourcePath: string;
|
|
mkdir?: boolean;
|
|
}): Promise<void> {
|
|
const root = await fsRoot(params.rootDir);
|
|
await root.copyIn(params.relativePath, params.sourcePath, {
|
|
mkdir: params.mkdir,
|
|
sourceHardlinks: "reject",
|
|
});
|
|
}
|