fix: reject absolute urls in the content resolver, register the mutants

Review CODE-REVIEW-225-r1.

M1: urlsplit(url).path was trusted even when the url carried a scheme or an
authority, so "https://evil.example/houseplan_files/files/m1/doc.pdf"
resolved onto a local file while _looks_internal kept calling it external —
the mirror image of the inconsistency this resolver exists to prevent. Only a
same-document reference is resolved by its path now.

M2: the three mutants the spec described are registered in
scripts/mutation-gate.mjs instead of living as a one-off manual run. The
traversal entry drops both structural checks at once on purpose: taken one at
a time the defence is layered (sanitize_marker_id turns ".." into "misc") and
the mutant would be equivalent — established by running it.

Issue: #225
User-Visible: no
This commit is contained in:
Codex
2026-08-20 22:00:22 +03:00
parent cb1e4cea64
commit 2935c293e1
3 changed files with 71 additions and 1 deletions
+20
View File
@@ -164,6 +164,26 @@ def test_issue_225_external_url_is_still_external(tmp_path: Path) -> None:
assert import_export_api._looks_internal("https://example.invalid/floor.svg?v=1") is False
@pytest.mark.parametrize("url", [
f"https://evil.example{FILES_URL}/m1/doc.pdf",
f"https://evil.example{CONTENT_URL}/files/m1/doc.pdf?v=1",
f"//evil.example{FILES_URL}/m1/doc.pdf",
f"https://evil.example{PLANS_URL}/f1.svg",
])
def test_issue_225_absolute_url_never_resolves_onto_a_local_file(
tmp_path: Path, url: str,
) -> None:
"""AC5: only a same-document reference may be resolved by its path.
A scheme or an authority means the path belongs to another host. Taking it
would let a crafted document describe an outside link as a local file —
the same inconsistency the resolver is meant to prevent, mirrored
(review CODE-REVIEW-225-r1, M1).
"""
assert import_export_api._internal_path(tmp_path, url) is None
assert import_export_api._looks_internal(url) is False
@pytest.mark.parametrize("same_source, expected_state, expected_confirmation", [
(True, "available", False),
(False, "detach_required", True),