31 lines
1.3 KiB
Markdown
31 lines
1.3 KiB
Markdown
# Spec: fix-can-edit-path-prefix
|
|||
|
|
|
||
|
|
## Problem
|
||
|
|
`--can-edit` and `--scope-check` in `scripts/status.py` use `str(file_path).startswith(proj_str)` to verify a file is within the project directory. String `startswith` matches sibling directories: `/home/user/project-evil/file.py` matches prefix `/home/user/project`. This allows editing files outside the project boundary.
|
||
|
|
|
||
|
|
Affected locations:
|
||
|
|
- `scripts/status.py:951` (`--can-edit --project --file`)
|
||
|
|
- `scripts/status.py:1004` (`--can-edit --task --file`, framework case)
|
||
|
|
- `scripts/status.py:1010` (`--can-edit --task --file`, regular project case)
|
||
|
|
- `scripts/status.py:1047` (`--scope-check`)
|
||
|
|
- `scripts/status.py:1052` (`--scope-check`, framework check)
|
||
|
|
|
||
|
|
## Fix
|
||
|
|
Append a trailing path separator to the prefix before comparison:
|
||
|
|
```python
|
||
|
|
str(file_path).startswith(proj_str + os.sep)
|
||
|
|
```
|
||
|
|
Or use `Path.relative_to()` which correctly resolves path boundaries:
|
||
|
|
```python
|
||
|
|
try:
|
||
|
|
file_path.relative_to(project_dir.resolve())
|
||
|
|
except ValueError:
|
||
|
|
# out of scope
|
||
|
|
```
|
||
|
|
|
||
|
|
## Acceptance Criteria
|
||
|
|
- A file in `/home/user/project-evil/` is correctly rejected as out-of-scope when project is `/home/user/project`
|
||
|
|
- A file in `/home/user/project/subdir/` is correctly accepted as in-scope
|
||
|
|
- Both framework and regular project cases work
|
||
|
|
- Add a test in `tests/test_status.py` covering the sibling-directory edge case
|