Minor Changes
-
#257
91cf7beThanks @tufantunc! -[policy].denylistpatterns are now also tested against the remote path of the five SFTP tools, not only against the command string this server composes for them (#230). A rule written for the path, such asauthorized_keys$, used to misssftp-upload-fileandsftp-download-file, whose strings end with the local path, and a spelling like/root//.ssh/slipped past a substring rule on every tool. The path is tested three ways: as given; lexically normalized (//and/./collapsed,..resolved, a trailing/dropped,\read as/); and in a Windows reading, tested case-insensitively — on Windows the case variants, a trailing run of dots and spaces, and the::$DATAdefault-stream spelling reach the same file (measured over SFTP on Windows 11), so a rule now catches them all; drive-relative spellings are rooted at their drive and UNC roots are kept. 8.3 short names (AUTHOR~1) and symlinks remain unresolved residuals. OPA's input gainsresource.remotePath,remotePathNormalizedandremotePathWindowsfor these tools.Upgrade note — minor, not patch, because a call that was allowed can now be refused. A pattern written for commands is now also tested against SFTP paths, so
^rmrefuses ansftp-downloadofrmlist.txt; and path rules match case-insensitively through the Windows reading, so on a case-sensitive target a rule onauthorized_keysnow also refusesAUTHORIZED_KEYS. The refusal says which reading matched. Nothing is resolved on the target: relative paths stay relative and symlinks are not followed, so anchor a path rule on its trailing segments.