fix(host): require complete UNC forms in the fully-qualified path check

ds-review-bot round 5: '\\' and '\\server' satisfy win32.isAbsolute and
the previous two-separator test, yet resolve() collapses them to
drive-relative roots. The UNC arm now requires server and share components;
incomplete prefixes reject with the business codes, covered per-platform.
This commit is contained in:
creatixchu
2026-07-28 18:27:26 +08:00
parent b211a80b1f
commit 987ecc2ec2
5 changed files with 13 additions and 8 deletions
@@ -76,11 +76,16 @@ describe('BrowseDirectoryPicker', () => {
expect(fullyQualified('C:\\projects', 'win32')).toBe(true)
expect(fullyQualified('C:/projects', 'win32')).toBe(true)
expect(fullyQualified('\\\\server\\share', 'win32')).toBe(true)
expect(fullyQualified('//server/share/deep', 'win32')).toBe(true)
// Rooted but drive-less: isAbsolute accepts these, yet resolve() would
// inject the process's current drive.
expect(fullyQualified('\\foo', 'win32')).toBe(false)
expect(fullyQualified('/foo', 'win32')).toBe(false)
expect(fullyQualified('C:relative', 'win32')).toBe(false)
// Incomplete UNC prefixes collapse to drive-relative roots under resolve().
expect(fullyQualified('\\\\', 'win32')).toBe(false)
expect(fullyQualified('\\\\server', 'win32')).toBe(false)
expect(fullyQualified('\\\\server\\', 'win32')).toBe(false)
})
it('rejects non-absolute paths instead of rebasing them under the process cwd', async () => {