// Media Core module implements inbound path policy behavior. import path from "node:path"; const WILDCARD_SEGMENT = "*"; const WINDOWS_DRIVE_ABS_RE = /^[A-Za-z]:\//; const WINDOWS_DRIVE_ROOT_RE = /^[A-Za-z]:$/; function normalizePosixAbsolutePath(value: string): string | undefined { const trimmed = value.trim(); if (!trimmed || trimmed.includes("\0")) { return undefined; } // Compare all roots as POSIX-style absolute paths so channel configs can use // stable patterns even when a source reports Windows separators. const normalized = path.posix.normalize(trimmed.replaceAll("\\", "/")); const isAbsolute = normalized.startsWith("/") || WINDOWS_DRIVE_ABS_RE.test(normalized); if (!isAbsolute || normalized === "/") { return undefined; } const withoutTrailingSlash = normalized.endsWith("/") ? normalized.slice(0, -1) : normalized; if (WINDOWS_DRIVE_ROOT_RE.test(withoutTrailingSlash)) { return undefined; } return WINDOWS_DRIVE_ABS_RE.test(withoutTrailingSlash) ? withoutTrailingSlash.toLowerCase() : withoutTrailingSlash; } function splitPathSegments(value: string): string[] { return value.split("/").filter(Boolean); } function matchesRootPattern(params: { candidatePath: string; rootPattern: string }): boolean { const candidateSegments = splitPathSegments(params.candidatePath); const rootSegments = splitPathSegments(params.rootPattern); if (candidateSegments.length < rootSegments.length) { return false; } for (let idx = 0; idx < rootSegments.length; idx += 1) { const expected = rootSegments[idx]; const actual = candidateSegments[idx]; if (expected === WILDCARD_SEGMENT) { continue; } if (expected !== actual) { return false; } } return true; } /** Validates an absolute inbound root pattern with whole-segment wildcards only. */ export function isValidInboundPathRootPattern(value: string): boolean { const normalized = normalizePosixAbsolutePath(value); if (!normalized) { return false; } const segments = splitPathSegments(normalized); if (segments.length === 0) { return false; } return segments.every((segment) => segment === WILDCARD_SEGMENT || !segment.includes("*")); } /** Normalizes configured inbound attachment roots, dropping invalid or duplicate patterns. */ export function normalizeInboundPathRoots(roots?: readonly string[]): string[] { const normalized: string[] = []; const seen = new Set(); for (const root of roots ?? []) { if (typeof root !== "string") { continue; } if (!isValidInboundPathRootPattern(root)) { continue; } const candidate = normalizePosixAbsolutePath(root); if (!candidate || seen.has(candidate)) { continue; } seen.add(candidate); normalized.push(candidate); } return normalized; } /** Merges inbound attachment root lists while preserving first-seen priority. */ export function mergeInboundPathRoots( ...rootsLists: Array ): string[] { const merged: string[] = []; const seen = new Set(); for (const roots of rootsLists) { const normalized = normalizeInboundPathRoots(roots); for (const root of normalized) { if (seen.has(root)) { continue; } seen.add(root); merged.push(root); } } return merged; } /** Checks whether a candidate inbound media path is covered by configured or fallback roots. */ export function isInboundPathAllowed(params: { filePath: string; roots: readonly string[]; fallbackRoots?: readonly string[]; }): boolean { const candidatePath = normalizePosixAbsolutePath(params.filePath); if (!candidatePath) { return false; } const roots = normalizeInboundPathRoots(params.roots); const effectiveRoots = roots.length > 0 ? roots : normalizeInboundPathRoots(params.fallbackRoots ?? undefined); if (effectiveRoots.length === 0) { return false; } return effectiveRoots.some((rootPattern) => matchesRootPattern({ candidatePath, rootPattern })); }