You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Orphan import no longer fails with a bogus symlink error: vocgit pull
imports failed with Invalid path: "..." escapes base directory through a symlink for every orphaned assignment because the symlink-hardened write
path treated a not-yet-created import directory as an escape (realpath on
the missing base). writeFileUnderBase now creates the trusted base
directory before running its confinement checks, restoring fresh imports
while keeping all symlink-escape rejections intact.
lti_url classified as a non-setting: Vocareum returns a server-derived
LTI launch URL on assignment reads. It is identity metadata (encodes the
course/assignment IDs), not an instructor-configurable setting, so it is now
dropped like part_url instead of being preserved under _unknown_settings
and flagged in the end-of-run unsupported-fields report.
Security
The user-typed import directory name is now confined to the workspace with
realpath-based validation (assertConfinedToWorkspace) before any directory
creation. A lexical-only check was insufficient: a name beneath an
in-workspace symlink that points outside the workspace would pass the lexical
test and let the import write outside the working tree.
Removed an accidental self-dependency (vocareum-publisher listed in its own dependencies) that caused a nested copy of the package to be installed.