From 8f433f543511e549c74802b545ba7b5e3cef8a26 Mon Sep 17 00:00:00 2001 From: anupamme Date: Wed, 19 Aug 2026 11:36:32 +0000 Subject: [PATCH] fix: the tools/view in view.js The tools/view --- tools/view.js | 27 +++++++++++++++------------ 1 file changed, 15 insertions(+), 12 deletions(-) diff --git a/tools/view.js b/tools/view.js index 27e8093..06e0acb 100644 --- a/tools/view.js +++ b/tools/view.js @@ -16,6 +16,13 @@ if (!exampleFile) { // Resolve the full path const fullPath = path.resolve(exampleFile); +// Restrict access to the examples directory only +const examplesDir = path.resolve(__dirname, "..", "examples"); +if (!fullPath.startsWith(examplesDir + path.sep)) { + console.error(`Error: File must be within the examples/ directory`); + process.exit(1); +} + if (!fs.existsSync(fullPath)) { console.error(`File not found: ${fullPath}`); process.exit(1); @@ -146,20 +153,16 @@ async function buildAndServe() { console.log("Build successful!"); // Create a simple HTTP server + // Pre-build allowed paths to avoid any user-input in path construction + const servedFiles = { + "/": path.join(tempDir, "index.html"), + "/bundle.js": path.join(tempDir, "bundle.js"), + "/bundle.js.map": path.join(tempDir, "bundle.js.map"), + }; const server = http.createServer((req, res) => { - let filePath = path.join( - tempDir, - req.url === "/" ? "index.html" : req.url, - ); - - // Security: prevent directory traversal - if (!filePath.startsWith(tempDir)) { - res.writeHead(403); - res.end("Forbidden"); - return; - } + const filePath = servedFiles[req.url]; - if (!fs.existsSync(filePath)) { + if (!filePath || !fs.existsSync(filePath)) { res.writeHead(404); res.end("Not found"); return;