diff options
| author | Saikari <[email protected]> | 2026-07-10 23:20:32 +0300 |
|---|---|---|
| committer | ruki <[email protected]> | 2026-07-30 10:17:31 +0800 |
| commit | dc0f11050075a727c68546b656e57c1d98a71022 (patch) | |
| tree | eb72138251a61ccc9fc0ee6d2454650e4f4205e5 /xmake/plugins/plugin/main.lua | |
| parent | 4b6a2eb23d0903124871f837798db2dd718e86a1 (diff) | |
fix: improve cache key generation and validate plugin names for removal
Diffstat (limited to 'xmake/plugins/plugin/main.lua')
| -rw-r--r-- | xmake/plugins/plugin/main.lua | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/xmake/plugins/plugin/main.lua b/xmake/plugins/plugin/main.lua index 1ab4d1a9e..4045fb053 100644 --- a/xmake/plugins/plugin/main.lua +++ b/xmake/plugins/plugin/main.lua @@ -201,6 +201,8 @@ end -- remove the given installed plugin function _remove() local name = assert(option.get("plugins"), "please specify the plugin name to be removed!") + -- avoid escaping the plugins directory, e.g. `xmake plugin --remove ../foo` + assert(not name:find("..", 1, true) and not name:find("[/\\:]"), "invalid plugin name(%s)!", name) local plugindir = path.join(global.directory(), "plugins", name) assert(os.isdir(plugindir), "plugin(%s) not found!", name) os.rmdir(plugindir) |
