The FilesystemFileSearchMiddleware incorrectly rejects any path containing two consecutive dots, blocking valid directory names like 'src..old'. This causes glob searches over legitimate files to return no results. A component-wise traversal check fixes the issue while preserving security.
The validation uses a substring check for '..' on the raw path string, treating all occurrences as traversal. This confuses harmless double-dot segments with the parent-directory component. The underlying design flaw is string-based path validation instead of parsing path components.
1. Create a directory named 'src..old' inside a temporary root directory. 2. Write a file 'file.py' inside 'src..old'. 3. Instantiate FilesystemFileSearchMiddleware with that root path. 4. Call middleware.glob_search.func(pattern='*.py', path='/src..old'). 5. Observe that the result is 'No files found' instead of the path to file.py.
Fixing Code Block
from pathlib import Path
# In FilesystemFileSearchMiddleware.glob_search, replace the validation block with:
if Path(path).is_absolute() or path.startswith("~") or any(part == ".." for part in Path(path).parts):
return "No files found"
The fix replaces the substring check for '..' with a component-wise check using Path.parts. This allows legitimate directory names like 'src..old' while still rejecting any actual '..' component. Absolute paths and paths starting with '~' are still blocked, preserving existing security boundaries.
Edge Case Audit
The fix assumes the path argument is a relative POSIX or Windows path. On Windows, Path.parts may include drive letters if the path is absolute, but the absolute check handles that. Ensure that the root_path is not itself a symlink or that other checks prevent symlink escapes; this component-based check alone does not resolve symlinks. Rolling back should restore the previous strict validation, but at the cost of rejecting legitimate double-dot segments. Thoroughly test with paths containing '..' in components and actual traversal attempts.