Documentation
¶
Overview ¶
Package validation provides input validation functions for the Entire CLI. This package has no dependencies to avoid import cycles.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ValidateAgentID ¶
ValidateAgentID validates that an agent ID contains only safe characters for paths.
func ValidateAgentSessionID ¶
ValidateAgentSessionID validates that an agent session ID contains only safe characters for paths. Agent session IDs can be UUIDs (Claude Code), test identifiers, or other formats depending on the agent. This prevents path traversal attacks when the ID is used in file path construction.
func ValidateFileNameComponent ¶ added in v0.11.1
ValidateFileNameComponent rejects names whose meaning can change when used as one filesystem component on a supported platform. It deliberately does not apply identifier-only rules such as rejecting leading dashes or glob syntax.
ONE component: a separator is rejected rather than split on. Callers do the splitting, and a validator that silently accepted "sub/../../../etc" because its only caller happened to split first is a trap for the second caller — note that "../x" passes every other rule here, and "../.." is caught only by the trailing-period check, so the mistake survives a casual smoke test.
func ValidateSessionID ¶
ValidateSessionID validates that a session ID doesn't contain path separators or other unsafe characters for use in file paths. This prevents path traversal attacks when session IDs are used in file paths.
func ValidateToolUseID ¶
ValidateToolUseID validates that a tool use ID contains only safe characters for paths. Tool use IDs can be UUIDs or prefixed identifiers like "toolu_xxx".
Types ¶
This section is empty.