fix: patch path traversal in export_report and create_set_template (v1.28.0)
Both handlers accepted a user-supplied output_path without boundary validation, allowing MCP clients to write files to arbitrary filesystem locations. A new safe_output_path() helper canonicalizes the parent directory and asserts the resolved path stays within the allowed base directory before any fs::write() call. Also fixes pre-existing unused-import/dead-code warnings that blocked the -D warnings release build. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
d41c51bae4
commit
2b136b845b
@@ -37,6 +37,7 @@ impl BacktestPreflight {
|
||||
}
|
||||
}
|
||||
|
||||
#[allow(dead_code)]
|
||||
fn is_ready(&self) -> bool {
|
||||
self.account.is_some() && !self.available_symbols.is_empty() && self.ea_exists
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user