summaryrefslogtreecommitdiff
path: root/xmake/plugins/plugin/main.lua
diff options
context:
space:
mode:
authorSaikari <[email protected]>2026-07-10 23:20:32 +0300
committerruki <[email protected]>2026-07-30 10:17:31 +0800
commitdc0f11050075a727c68546b656e57c1d98a71022 (patch)
treeeb72138251a61ccc9fc0ee6d2454650e4f4205e5 /xmake/plugins/plugin/main.lua
parent4b6a2eb23d0903124871f837798db2dd718e86a1 (diff)
fix: improve cache key generation and validate plugin names for removal
Diffstat (limited to 'xmake/plugins/plugin/main.lua')
-rw-r--r--xmake/plugins/plugin/main.lua2
1 files changed, 2 insertions, 0 deletions
diff --git a/xmake/plugins/plugin/main.lua b/xmake/plugins/plugin/main.lua
index 1ab4d1a9e..4045fb053 100644
--- a/xmake/plugins/plugin/main.lua
+++ b/xmake/plugins/plugin/main.lua
@@ -201,6 +201,8 @@ end
-- remove the given installed plugin
function _remove()
local name = assert(option.get("plugins"), "please specify the plugin name to be removed!")
+ -- avoid escaping the plugins directory, e.g. `xmake plugin --remove ../foo`
+ assert(not name:find("..", 1, true) and not name:find("[/\\:]"), "invalid plugin name(%s)!", name)
local plugindir = path.join(global.directory(), "plugins", name)
assert(os.isdir(plugindir), "plugin(%s) not found!", name)
os.rmdir(plugindir)