fix(site-publish): reject split input symlinks
Test / contract (pull_request) Successful in 6s

Authored-By: OpenAI (GPT-5) <noreply@openai.com>
This commit is contained in:
Evelyn Chen
2026-08-29 22:30:43 +00:00
parent fb2e440bbb
commit 7b824a61ca
3 changed files with 23 additions and 2 deletions
+3 -2
View File
@@ -136,8 +136,9 @@ provisional cache policy or a pointer to a missing immutable target.
Artifact input directories must be pairwise disjoint after filesystem
resolution. Publication stops before build or upload if one contains another or
escapes the repository, preventing protected input from entering a public
artifact. Split storage endpoints are pinned to Garage, and each website
escapes the repository. Descendant symlinks are also rejected, preventing
protected input from entering a public artifact through dereference. Split
storage endpoints are pinned to Garage, and each website
authority is derived from its bucket; a site cannot expose an arbitrary backend.
Each split route gets a bucket-specific `<bucket>.web.sjc001.fritzlab.net`