-
Notifications
You must be signed in to change notification settings - Fork 3
plat 440
| Coordination | Value |
|---|---|
| State | open (found while doing PLAT-435; not fixed) |
| Date | 2026-10-04 |
| Owner | security-sandbox |
workspaceref.SanitizeUserID (and sanitizeUserIDForPath, the pkg/common and pkg/chathistory copies it replaced)
maps an empty, over-long or odd user id to "default". Several places build a physical path from a user id without
that rule, or with a different one, so for an id outside [a-zA-Z0-9_-] they name a folder the rest of the system
never uses:
-
cmd/server/multiagent_config_store.gomultiAgentConfigPath,services/workspace_config.goLoadMultiAgentChatCapabilities,services/bot_connector.goloadRecentChatTurns,pkg/workspace/client.gofolder-guard rewrite: rawuserID. -
services/whatsapp_service.goandservices/slack_service.goupload folders:sanitizeWhatsAppFileName, a file-name sanitizer, not the path rule. -
workspace/utils.SanitizeUserID(the workspace module) falls back toGetDefaultUserID()(theDEFAULT_USER_IDenv var), the agent server falls back to the literal"default": the two disagree wheneverDEFAULT_USER_IDis set.
Normal accounts have valid ids, so nothing is known to break today; the risk is the same class as PLAT-435 (works on the common path, wrong on an unusual one).
Decide the rule (one sanitizer, one default), then switch these call sites from workspaceref.PhysicalPathOf (marks
"owner not sanitized"; grep PhysicalPathOf) to workspaceref.PhysicalPath, with a test using an odd id. Align the
workspace module's fallback.
Auto-synced from docs/ on main. Edit there, not here.