Skip to content

v2.18.0

Latest

Choose a tag to compare

@github-actions github-actions released this 04 Oct 14:33
723a7c5

Minor Changes

  • #257 91cf7be Thanks @tufantunc! - [policy].denylist patterns are now also tested against the remote path of the five SFTP tools, not only against the command string this server composes for them (#230). A rule written for the path, such as authorized_keys$, used to miss sftp-upload-file and sftp-download-file, whose strings end with the local path, and a spelling like /root//.ssh/ slipped past a substring rule on every tool. The path is tested three ways: as given; lexically normalized (// and /./ collapsed, .. resolved, a trailing / dropped, \ read as /); and in a Windows reading, tested case-insensitively — on Windows the case variants, a trailing run of dots and spaces, and the ::$DATA default-stream spelling reach the same file (measured over SFTP on Windows 11), so a rule now catches them all; drive-relative spellings are rooted at their drive and UNC roots are kept. 8.3 short names (AUTHOR~1) and symlinks remain unresolved residuals. OPA's input gains resource.remotePath, remotePathNormalized and remotePathWindows for these tools.

    Upgrade note — minor, not patch, because a call that was allowed can now be refused. A pattern written for commands is now also tested against SFTP paths, so ^rm refuses an sftp-download of rmlist.txt; and path rules match case-insensitively through the Windows reading, so on a case-sensitive target a rule on authorized_keys now also refuses AUTHORIZED_KEYS. The refusal says which reading matched. Nothing is resolved on the target: relative paths stay relative and symlinks are not followed, so anchor a path rule on its trailing segments.