Skip to content

feat: secure project name and destination validation - #65

Merged
dDevAhmed merged 5 commits into
mainfrom
feat/cli-024-project-validation
Sep 8, 2026
Merged

dDevAhmed merged 5 commits into
mainfrom
feat/cli-024-project-validation

Conversation

@dDevAhmed

Copy link
Copy Markdown
Contributor

Summary

Implements CLI-024 by adding the first filesystem/path security boundary for stellarforge new.

Included

  • validates project names before destination planning
  • rejects . / .., POSIX and Windows-style traversal/path input, absolute/path-like names, hidden-leading-dot names, unsafe characters, and Windows reserved device names
  • resolves the working directory before planning
  • requires the project destination to remain inside the resolved working directory
  • refuses destinations occupied by files
  • refuses existing non-empty directories with an explicit no-overwrite MVP policy
  • allows existing empty directories
  • performs no filesystem writes during validation/planning
  • integrates the secure validator/planner into the default new command services
  • adds POSIX/Windows-relevant malicious-input and destination-conflict tests

Security

  • no overwrite prompt or implicit force behavior
  • no traversal outside the generation root
  • no shell/process execution
  • validation/planning are read-only
  • errors are explicit and do not dump filesystem contents

Closes #27

@dDevAhmed
dDevAhmed merged commit 9e66734 into main Sep 8, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CLI-024 — Implement project name and destination validation

1 participant