Allow relative imports with two dots at start of path. Update unit tests.

This commit is contained in:
Beth Probert 2026-03-06 14:13:00 +00:00
parent e5429d6cda
commit 4395d4001c
2 changed files with 9 additions and 10 deletions

View file

@ -140,11 +140,11 @@ def make_path_safe(unsafe_path_string: str) -> str:
for i, component in enumerate(components):
if component in ("/", "\\"):
sanitised_components.append(component)
elif component == ".":
# Only allow '.' if its the very first
# element and the next element is a separator.
# This allows for relative paths like "./file"
# but not "file./file"
elif component in (".", ".."):
# Only allow '.' and '..' if they are the very first
# elements and the next element is a separator.
# This allows for relative paths like "./file" or "../file"
# but not "file./file" or "file/../file"
is_first = i == 0
next_to_sep = (i + 1 < len(components)) and (
components[i + 1] in ("/", "\\")

View file

@ -95,13 +95,12 @@ def test_make_path_safe_separators():
def test_make_path_safe_relative():
"""Test that relative path components are preserved.
We only allow relative paths with one dot, and at the beginning of the path,
to avoid issues with paths like "file./file" or "file../file
"""
"""Test that relative path components are preserved."""
# We only allow relative paths with one dot, and at the beginning of the path,
# to avoid issues with paths like "file./file" or "file../file.
assert make_path_safe("./openflexure/data/") == "./openflexure/data/"
assert make_path_safe("../openflexure/data/") == "../openflexure/data/"
assert make_path_safe("../openflexure/data/") == "_/openflexure/data/"
assert make_path_safe("path/./to/file") == "path/_/to/file"
assert make_path_safe("path/../to/file") == "path/_/to/file"
assert make_path_safe(".") == "_"