Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs - #1920

Merged
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal
May 22, 2026
Merged

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs#1920
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal

Conversation

@TooTallNate

Copy link
Copy Markdown
Member

Summary

Backport of #1829 (security fix) to the stable branch.

Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId, stream names, and tags) flowed directly into path.join() calls in @workflow/world-local, allowing a client to send values like ../../../package and cause the backend to read or write files outside the workflow data directory.

This adds a centralized validator (assertSafeEntityId) that rejects IDs which are empty, start with ., or contain path separators or NUL bytes, and applies it at every storage-layer entry point that composes IDs into filesystem paths.

Backport details

The cherry-pick applied cleanly except for two files where stable's pre-v5 shape diverged from main:

  • packages/world-local/src/storage/steps-storage.ts — Stable's steps.get() accepts an optional runId and looks it up via listJSONFiles when missing; main's signature requires runId. Resolution: assert stepId always, and only assert runId when it was supplied (the disk lookup only ever produces internal-derived runIds, so it can't be attacker-controlled).
  • packages/world-local/src/streamer.ts — Stable still has the v4 streamer interface (separate closeStream / listStreamsByRunId / getStreamChunks methods rather than main's renamed equivalents). The auto-merge produced a stray duplicate block that conflicted with stable's existing getStreamChunks chunk-walking loop. Resolution: kept stable's existing loop; threaded the assertSafeEntityId('runId', runId) call into stable's listStreamsByRunId. The other three call sites (listChunkFilesForStream, registerStreamForRun, plus the import) auto-merged correctly.

All 339 tests in packages/world-local pass, including the new path-traversal test cases (60 in fs.test.ts covering assertSafeEntityId, UnsafeEntityIdError, error truncation, etc.). Workspace pnpm typecheck is clean.

Test plan

cd packages/world-local && pnpm test
pnpm turbo build --filter @workflow/world-local
pnpm typecheck

)
* fix(world-local): prevent path traversal via request-supplied IDs
Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId,
stream names, and tags) flowed directly into path.join() calls, allowing a
client to send values like '../../../package' and cause the backend to read
or write files outside the workflow data directory.
Add a centralized validator (assertSafeEntityId) that rejects IDs which are
empty, start with '.', or contain path separators or NUL bytes. Apply it at
each storage-layer entry point that composes IDs into filesystem paths:
fs.taggedPath / readJSONWithFallback / paginatedFileSystemQuery, the runs /
steps / events / hooks storage methods, and the streamer.
* address review feedback
- UnsafeEntityIdError now extends WorkflowWorldError for consistency with
other storage-layer errors and the platform error-to-HTTP mapping.
- Add resolveWithinBase(basedir, ...segments) containment helper and
apply it at every taggedPath / readJSONWithFallback / .locks path
construction site in events-storage and legacy, so a forgotten
assertSafeEntityId at a future call site can't silently regress.
- Truncate attacker-controlled values in the error message.
- Drop unused assertSafeEntityIds helper and the unreachable typeof
check under the TS signature.
- Fix docstrings on assertSafeEntityId / taggedPath JSDoc example /
filePrefix validation comment to match what the code actually does.
- handleLegacyEvent now re-asserts runId locally so the invariant is
documented at the call site instead of implicitly inherited from
events.create.
---------
Co-authored-by: JJ Kasper <jj@jjsweb.site>
CopilotAI review requested due to automatic review settings May 4, 2026 19:58
@changeset-bot

changeset-botBot commented May 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0600f5f

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@workflow/world-localPatch
@workflow/cliPatch
@workflow/corePatch
@workflow/vitestPatch
@workflow/world-postgresPatch
workflowPatch
@workflow/world-testingPatch
@workflow/buildersPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actionsBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
❌ ▲ Vercel Production898367968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4403723614836

❌ Failed Tests

▲ Vercel Production (3 failed)

nextjs-webpack (1 failed):

  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R | 🔍 observability

nitro (1 failed):

  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09 | 🔍 observability

nuxt (1 failed):

  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0 | 🔍 observability
🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS8MGHFZ6KS45FVEW0XQX7V4
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS8MEN5F3KCSEK0QSW06CTT8
  • promiseRaceWorkflow | wrun_01KS8MESSXSM2C1353G8A5ZKNB
  • promiseAnyWorkflow | wrun_01KS8MEWB1AEWPZB0YTKJPYF5D
  • importedStepOnlyWorkflow | wrun_01KS8MGVXGWGZKAG56SZJ49K71
  • readableStreamWorkflow | wrun_01KS8MEYM1H7RRPMXEX8MQ3PHX
  • hookWorkflow | wrun_01KS8MFAQBXA9A3VFSDWYDHDWC
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS8MFJG7KZXNKDJNWDJ79Z88
  • webhookWorkflow | wrun_01KS8MFQDT9Y5CXXESREAWEHNW
  • sleepingWorkflow | wrun_01KS8MFY89KFYS10VK4TRNJT2P
  • parallelSleepWorkflow | wrun_01KS8MGDZ32T0NX5BB7Y77XF3Y
  • nullByteWorkflow | wrun_01KS8MGHE40E6ABNDA9E699V71
  • workflowAndStepMetadataWorkflow | wrun_01KS8MGM29HGDP86NM0FN49JGA
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS8MK2VEWW2YK1965TDPA1SP
  • fetchWorkflow | wrun_01KS8MKHF9QEHE5V3HQ28A74QS
  • promiseRaceStressTestWorkflow | wrun_01KS8MKN1TMEAPJTS92Y9ASHNQ
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS8MQ40N6R2PHEQ6YEC8KZS7
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS8MQGQ96G58SQ3C41MYMX56
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS8MRW8PNZ19JMHAG8VM59MY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS8MS2ETVR65YA5N1ENFP8X1
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS8MS4N6V6EERRYVVTY949TS
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS8MSVM5PMDAC29E0YVB07DV
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS8MT2HKAQ41FVAM91P2M8BK
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS8MTAC9C7QW3DTTP264TYS2
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS8MTH9G0JDXPSJA33041NT3
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS8MTREN07PM8ZSX64ZCXQBY
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS8MV0174CV1S586WDRMA532
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS8MVFAX6EJTRM8YC3ZVS9BB
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS8MVRVM9R89WWMRC7YK1X90
  • cancelRun - cancelling a running workflow | wrun_01KS8MVZX080BHGXNR2J43H8S5
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS8MW9D8MEMXTRE971ZC7NWJ
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS8MWQA4NBWBGVZ5FA5E169W
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS8MX7PW79NDPP3TSMQR87JY
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS8MXJ9QWW067NCK4YRV9NET
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS8MXSN3SN2YV62CQ6CMTQZR
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS8MXW5SF5Y9RT5WDMKY2F4K
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS8MXYARJCH4FXKT1NSQK98G

Details by Category

❌ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
❌ nextjs-webpack8512
❌ nitro8017
❌ nuxt8017
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run


Some E2E test jobs failed:

  • Vercel Prod: failure
  • Local Dev: success
  • Local Prod: success
  • Local Postgres: success
  • Windows: success

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backport of the world-local path-traversal fix from main to stable, adding centralized ID validation and applying it across filesystem-backed storage paths so request-supplied identifiers cannot escape the local workflow data directory.

Changes:

  • Added assertSafeEntityId, UnsafeEntityIdError, and resolveWithinBase in fs.ts to validate IDs and enforce path containment.
  • Threaded ID validation through runs, steps, events, hooks, legacy handling, and streamer storage paths.
  • Added regression tests for filesystem helpers and storage-layer traversal cases, plus a changeset for the patch release.

Reviewed changes

Copilot reviewed 10 out of 10 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
packages/world-local/src/streamer.tsValidates stream names/run IDs before building stream metadata and chunk paths.
packages/world-local/src/storage/steps-storage.tsValidates stepId and optional caller-supplied runId in step lookups/listing.
packages/world-local/src/storage/runs-storage.tsValidates runId before reading run JSON.
packages/world-local/src/storage/legacy.tsAdds local runId validation and switches legacy writes to contained path resolution.
packages/world-local/src/storage/hooks-storage.tsValidates hookId before reading hook JSON.
packages/world-local/src/storage/events-storage.tsAdds request-ID validation and containment checks for event/lock-path handling.
packages/world-local/src/storage.test.tsAdds storage-level regression tests for traversal attempts.
packages/world-local/src/fs.tsIntroduces centralized ID/path safety helpers and applies them in shared FS utilities.
packages/world-local/src/fs.test.tsAdds unit tests for ID validation, error behavior, and base-dir containment.
.changeset/world-local-path-traversal.mdDeclares the patch release note for @workflow/world-local.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadpackages/world-local/src/fs.ts Outdated
Comment threadpackages/world-local/src/storage/events-storage.ts Outdated
Comment threadpackages/world-local/src/streamer.ts
…ests
Addresses code review feedback on the path-traversal backport:
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
- Add streamer regression tests covering writeToStream, closeStream,
listStreamsByRunId, and getStreamChunks (the v4-shape surface that
this backport touches independently of main).
@TooTallNate
TooTallNate merged commit 5f50bbc into stableMay 22, 2026
86 of 91 checks passed
@TooTallNate
TooTallNate deleted the nathan/backport-1829-path-traversal branch May 22, 2026 20:28
TooTallNate added a commit that referenced this pull request May 22, 2026
* fix(world-local): tighten ID validation
Forward-port of code review fixes from #1920 (backport of #1829):
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
The streamer regression tests from #1920 are not forward-ported because
main's streamer surface differs (renamed methods, separate test
coverage) from stable's v4 shape.
* simplify changeset
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@TooTallNate@ijjk
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs - #1920

Merged
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal
May 22, 2026
Merged

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs#1920
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal

Conversation

@TooTallNate

Copy link
Copy Markdown
Member

Summary

Backport of #1829 (security fix) to the stable branch.

Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId, stream names, and tags) flowed directly into path.join() calls in @workflow/world-local, allowing a client to send values like ../../../package and cause the backend to read or write files outside the workflow data directory.

This adds a centralized validator (assertSafeEntityId) that rejects IDs which are empty, start with ., or contain path separators or NUL bytes, and applies it at every storage-layer entry point that composes IDs into filesystem paths.

Backport details

The cherry-pick applied cleanly except for two files where stable's pre-v5 shape diverged from main:

  • packages/world-local/src/storage/steps-storage.ts — Stable's steps.get() accepts an optional runId and looks it up via listJSONFiles when missing; main's signature requires runId. Resolution: assert stepId always, and only assert runId when it was supplied (the disk lookup only ever produces internal-derived runIds, so it can't be attacker-controlled).
  • packages/world-local/src/streamer.ts — Stable still has the v4 streamer interface (separate closeStream / listStreamsByRunId / getStreamChunks methods rather than main's renamed equivalents). The auto-merge produced a stray duplicate block that conflicted with stable's existing getStreamChunks chunk-walking loop. Resolution: kept stable's existing loop; threaded the assertSafeEntityId('runId', runId) call into stable's listStreamsByRunId. The other three call sites (listChunkFilesForStream, registerStreamForRun, plus the import) auto-merged correctly.

All 339 tests in packages/world-local pass, including the new path-traversal test cases (60 in fs.test.ts covering assertSafeEntityId, UnsafeEntityIdError, error truncation, etc.). Workspace pnpm typecheck is clean.

Test plan

cd packages/world-local && pnpm test
pnpm turbo build --filter @workflow/world-local
pnpm typecheck

)
* fix(world-local): prevent path traversal via request-supplied IDs
Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId,
stream names, and tags) flowed directly into path.join() calls, allowing a
client to send values like '../../../package' and cause the backend to read
or write files outside the workflow data directory.
Add a centralized validator (assertSafeEntityId) that rejects IDs which are
empty, start with '.', or contain path separators or NUL bytes. Apply it at
each storage-layer entry point that composes IDs into filesystem paths:
fs.taggedPath / readJSONWithFallback / paginatedFileSystemQuery, the runs /
steps / events / hooks storage methods, and the streamer.
* address review feedback
- UnsafeEntityIdError now extends WorkflowWorldError for consistency with
other storage-layer errors and the platform error-to-HTTP mapping.
- Add resolveWithinBase(basedir, ...segments) containment helper and
apply it at every taggedPath / readJSONWithFallback / .locks path
construction site in events-storage and legacy, so a forgotten
assertSafeEntityId at a future call site can't silently regress.
- Truncate attacker-controlled values in the error message.
- Drop unused assertSafeEntityIds helper and the unreachable typeof
check under the TS signature.
- Fix docstrings on assertSafeEntityId / taggedPath JSDoc example /
filePrefix validation comment to match what the code actually does.
- handleLegacyEvent now re-asserts runId locally so the invariant is
documented at the call site instead of implicitly inherited from
events.create.
---------
Co-authored-by: JJ Kasper <jj@jjsweb.site>
CopilotAI review requested due to automatic review settings May 4, 2026 19:58
@changeset-bot

changeset-botBot commented May 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0600f5f

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@workflow/world-localPatch
@workflow/cliPatch
@workflow/corePatch
@workflow/vitestPatch
@workflow/world-postgresPatch
workflowPatch
@workflow/world-testingPatch
@workflow/buildersPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actionsBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
❌ ▲ Vercel Production898367968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4403723614836

❌ Failed Tests

▲ Vercel Production (3 failed)

nextjs-webpack (1 failed):

  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R | 🔍 observability

nitro (1 failed):

  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09 | 🔍 observability

nuxt (1 failed):

  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0 | 🔍 observability
🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS8MGHFZ6KS45FVEW0XQX7V4
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS8MEN5F3KCSEK0QSW06CTT8
  • promiseRaceWorkflow | wrun_01KS8MESSXSM2C1353G8A5ZKNB
  • promiseAnyWorkflow | wrun_01KS8MEWB1AEWPZB0YTKJPYF5D
  • importedStepOnlyWorkflow | wrun_01KS8MGVXGWGZKAG56SZJ49K71
  • readableStreamWorkflow | wrun_01KS8MEYM1H7RRPMXEX8MQ3PHX
  • hookWorkflow | wrun_01KS8MFAQBXA9A3VFSDWYDHDWC
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS8MFJG7KZXNKDJNWDJ79Z88
  • webhookWorkflow | wrun_01KS8MFQDT9Y5CXXESREAWEHNW
  • sleepingWorkflow | wrun_01KS8MFY89KFYS10VK4TRNJT2P
  • parallelSleepWorkflow | wrun_01KS8MGDZ32T0NX5BB7Y77XF3Y
  • nullByteWorkflow | wrun_01KS8MGHE40E6ABNDA9E699V71
  • workflowAndStepMetadataWorkflow | wrun_01KS8MGM29HGDP86NM0FN49JGA
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS8MK2VEWW2YK1965TDPA1SP
  • fetchWorkflow | wrun_01KS8MKHF9QEHE5V3HQ28A74QS
  • promiseRaceStressTestWorkflow | wrun_01KS8MKN1TMEAPJTS92Y9ASHNQ
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS8MQ40N6R2PHEQ6YEC8KZS7
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS8MQGQ96G58SQ3C41MYMX56
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS8MRW8PNZ19JMHAG8VM59MY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS8MS2ETVR65YA5N1ENFP8X1
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS8MS4N6V6EERRYVVTY949TS
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS8MSVM5PMDAC29E0YVB07DV
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS8MT2HKAQ41FVAM91P2M8BK
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS8MTAC9C7QW3DTTP264TYS2
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS8MTH9G0JDXPSJA33041NT3
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS8MTREN07PM8ZSX64ZCXQBY
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS8MV0174CV1S586WDRMA532
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS8MVFAX6EJTRM8YC3ZVS9BB
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS8MVRVM9R89WWMRC7YK1X90
  • cancelRun - cancelling a running workflow | wrun_01KS8MVZX080BHGXNR2J43H8S5
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS8MW9D8MEMXTRE971ZC7NWJ
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS8MWQA4NBWBGVZ5FA5E169W
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS8MX7PW79NDPP3TSMQR87JY
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS8MXJ9QWW067NCK4YRV9NET
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS8MXSN3SN2YV62CQ6CMTQZR
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS8MXW5SF5Y9RT5WDMKY2F4K
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS8MXYARJCH4FXKT1NSQK98G

Details by Category

❌ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
❌ nextjs-webpack8512
❌ nitro8017
❌ nuxt8017
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run


Some E2E test jobs failed:

  • Vercel Prod: failure
  • Local Dev: success
  • Local Prod: success
  • Local Postgres: success
  • Windows: success

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backport of the world-local path-traversal fix from main to stable, adding centralized ID validation and applying it across filesystem-backed storage paths so request-supplied identifiers cannot escape the local workflow data directory.

Changes:

  • Added assertSafeEntityId, UnsafeEntityIdError, and resolveWithinBase in fs.ts to validate IDs and enforce path containment.
  • Threaded ID validation through runs, steps, events, hooks, legacy handling, and streamer storage paths.
  • Added regression tests for filesystem helpers and storage-layer traversal cases, plus a changeset for the patch release.

Reviewed changes

Copilot reviewed 10 out of 10 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
packages/world-local/src/streamer.tsValidates stream names/run IDs before building stream metadata and chunk paths.
packages/world-local/src/storage/steps-storage.tsValidates stepId and optional caller-supplied runId in step lookups/listing.
packages/world-local/src/storage/runs-storage.tsValidates runId before reading run JSON.
packages/world-local/src/storage/legacy.tsAdds local runId validation and switches legacy writes to contained path resolution.
packages/world-local/src/storage/hooks-storage.tsValidates hookId before reading hook JSON.
packages/world-local/src/storage/events-storage.tsAdds request-ID validation and containment checks for event/lock-path handling.
packages/world-local/src/storage.test.tsAdds storage-level regression tests for traversal attempts.
packages/world-local/src/fs.tsIntroduces centralized ID/path safety helpers and applies them in shared FS utilities.
packages/world-local/src/fs.test.tsAdds unit tests for ID validation, error behavior, and base-dir containment.
.changeset/world-local-path-traversal.mdDeclares the patch release note for @workflow/world-local.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadpackages/world-local/src/fs.ts Outdated
Comment threadpackages/world-local/src/storage/events-storage.ts Outdated
Comment threadpackages/world-local/src/streamer.ts
…ests
Addresses code review feedback on the path-traversal backport:
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
- Add streamer regression tests covering writeToStream, closeStream,
listStreamsByRunId, and getStreamChunks (the v4-shape surface that
this backport touches independently of main).
@TooTallNate
TooTallNate merged commit 5f50bbc into stableMay 22, 2026
86 of 91 checks passed
@TooTallNate
TooTallNate deleted the nathan/backport-1829-path-traversal branch May 22, 2026 20:28
TooTallNate added a commit that referenced this pull request May 22, 2026
* fix(world-local): tighten ID validation
Forward-port of code review fixes from #1920 (backport of #1829):
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
The streamer regression tests from #1920 are not forward-ported because
main's streamer surface differs (renamed methods, separate test
coverage) from stable's v4 shape.
* simplify changeset
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@TooTallNate@ijjk
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs - #1920

Merged
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal
May 22, 2026
Merged

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs#1920
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal

Conversation

@TooTallNate

Copy link
Copy Markdown
Member

Summary

Backport of #1829 (security fix) to the stable branch.

Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId, stream names, and tags) flowed directly into path.join() calls in @workflow/world-local, allowing a client to send values like ../../../package and cause the backend to read or write files outside the workflow data directory.

This adds a centralized validator (assertSafeEntityId) that rejects IDs which are empty, start with ., or contain path separators or NUL bytes, and applies it at every storage-layer entry point that composes IDs into filesystem paths.

Backport details

The cherry-pick applied cleanly except for two files where stable's pre-v5 shape diverged from main:

  • packages/world-local/src/storage/steps-storage.ts — Stable's steps.get() accepts an optional runId and looks it up via listJSONFiles when missing; main's signature requires runId. Resolution: assert stepId always, and only assert runId when it was supplied (the disk lookup only ever produces internal-derived runIds, so it can't be attacker-controlled).
  • packages/world-local/src/streamer.ts — Stable still has the v4 streamer interface (separate closeStream / listStreamsByRunId / getStreamChunks methods rather than main's renamed equivalents). The auto-merge produced a stray duplicate block that conflicted with stable's existing getStreamChunks chunk-walking loop. Resolution: kept stable's existing loop; threaded the assertSafeEntityId('runId', runId) call into stable's listStreamsByRunId. The other three call sites (listChunkFilesForStream, registerStreamForRun, plus the import) auto-merged correctly.

All 339 tests in packages/world-local pass, including the new path-traversal test cases (60 in fs.test.ts covering assertSafeEntityId, UnsafeEntityIdError, error truncation, etc.). Workspace pnpm typecheck is clean.

Test plan

cd packages/world-local && pnpm test
pnpm turbo build --filter @workflow/world-local
pnpm typecheck

)
* fix(world-local): prevent path traversal via request-supplied IDs
Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId,
stream names, and tags) flowed directly into path.join() calls, allowing a
client to send values like '../../../package' and cause the backend to read
or write files outside the workflow data directory.
Add a centralized validator (assertSafeEntityId) that rejects IDs which are
empty, start with '.', or contain path separators or NUL bytes. Apply it at
each storage-layer entry point that composes IDs into filesystem paths:
fs.taggedPath / readJSONWithFallback / paginatedFileSystemQuery, the runs /
steps / events / hooks storage methods, and the streamer.
* address review feedback
- UnsafeEntityIdError now extends WorkflowWorldError for consistency with
other storage-layer errors and the platform error-to-HTTP mapping.
- Add resolveWithinBase(basedir, ...segments) containment helper and
apply it at every taggedPath / readJSONWithFallback / .locks path
construction site in events-storage and legacy, so a forgotten
assertSafeEntityId at a future call site can't silently regress.
- Truncate attacker-controlled values in the error message.
- Drop unused assertSafeEntityIds helper and the unreachable typeof
check under the TS signature.
- Fix docstrings on assertSafeEntityId / taggedPath JSDoc example /
filePrefix validation comment to match what the code actually does.
- handleLegacyEvent now re-asserts runId locally so the invariant is
documented at the call site instead of implicitly inherited from
events.create.
---------
Co-authored-by: JJ Kasper <jj@jjsweb.site>
CopilotAI review requested due to automatic review settings May 4, 2026 19:58
@changeset-bot

changeset-botBot commented May 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0600f5f

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@workflow/world-localPatch
@workflow/cliPatch
@workflow/corePatch
@workflow/vitestPatch
@workflow/world-postgresPatch
workflowPatch
@workflow/world-testingPatch
@workflow/buildersPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actionsBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
❌ ▲ Vercel Production898367968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4403723614836

❌ Failed Tests

▲ Vercel Production (3 failed)

nextjs-webpack (1 failed):

  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R | 🔍 observability

nitro (1 failed):

  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09 | 🔍 observability

nuxt (1 failed):

  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0 | 🔍 observability
🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS8MGHFZ6KS45FVEW0XQX7V4
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS8MEN5F3KCSEK0QSW06CTT8
  • promiseRaceWorkflow | wrun_01KS8MESSXSM2C1353G8A5ZKNB
  • promiseAnyWorkflow | wrun_01KS8MEWB1AEWPZB0YTKJPYF5D
  • importedStepOnlyWorkflow | wrun_01KS8MGVXGWGZKAG56SZJ49K71
  • readableStreamWorkflow | wrun_01KS8MEYM1H7RRPMXEX8MQ3PHX
  • hookWorkflow | wrun_01KS8MFAQBXA9A3VFSDWYDHDWC
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS8MFJG7KZXNKDJNWDJ79Z88
  • webhookWorkflow | wrun_01KS8MFQDT9Y5CXXESREAWEHNW
  • sleepingWorkflow | wrun_01KS8MFY89KFYS10VK4TRNJT2P
  • parallelSleepWorkflow | wrun_01KS8MGDZ32T0NX5BB7Y77XF3Y
  • nullByteWorkflow | wrun_01KS8MGHE40E6ABNDA9E699V71
  • workflowAndStepMetadataWorkflow | wrun_01KS8MGM29HGDP86NM0FN49JGA
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS8MK2VEWW2YK1965TDPA1SP
  • fetchWorkflow | wrun_01KS8MKHF9QEHE5V3HQ28A74QS
  • promiseRaceStressTestWorkflow | wrun_01KS8MKN1TMEAPJTS92Y9ASHNQ
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS8MQ40N6R2PHEQ6YEC8KZS7
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS8MQGQ96G58SQ3C41MYMX56
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS8MRW8PNZ19JMHAG8VM59MY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS8MS2ETVR65YA5N1ENFP8X1
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS8MS4N6V6EERRYVVTY949TS
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS8MSVM5PMDAC29E0YVB07DV
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS8MT2HKAQ41FVAM91P2M8BK
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS8MTAC9C7QW3DTTP264TYS2
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS8MTH9G0JDXPSJA33041NT3
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS8MTREN07PM8ZSX64ZCXQBY
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS8MV0174CV1S586WDRMA532
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS8MVFAX6EJTRM8YC3ZVS9BB
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS8MVRVM9R89WWMRC7YK1X90
  • cancelRun - cancelling a running workflow | wrun_01KS8MVZX080BHGXNR2J43H8S5
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS8MW9D8MEMXTRE971ZC7NWJ
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS8MWQA4NBWBGVZ5FA5E169W
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS8MX7PW79NDPP3TSMQR87JY
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS8MXJ9QWW067NCK4YRV9NET
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS8MXSN3SN2YV62CQ6CMTQZR
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS8MXW5SF5Y9RT5WDMKY2F4K
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS8MXYARJCH4FXKT1NSQK98G

Details by Category

❌ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
❌ nextjs-webpack8512
❌ nitro8017
❌ nuxt8017
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run


Some E2E test jobs failed:

  • Vercel Prod: failure
  • Local Dev: success
  • Local Prod: success
  • Local Postgres: success
  • Windows: success

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backport of the world-local path-traversal fix from main to stable, adding centralized ID validation and applying it across filesystem-backed storage paths so request-supplied identifiers cannot escape the local workflow data directory.

Changes:

  • Added assertSafeEntityId, UnsafeEntityIdError, and resolveWithinBase in fs.ts to validate IDs and enforce path containment.
  • Threaded ID validation through runs, steps, events, hooks, legacy handling, and streamer storage paths.
  • Added regression tests for filesystem helpers and storage-layer traversal cases, plus a changeset for the patch release.

Reviewed changes

Copilot reviewed 10 out of 10 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
packages/world-local/src/streamer.tsValidates stream names/run IDs before building stream metadata and chunk paths.
packages/world-local/src/storage/steps-storage.tsValidates stepId and optional caller-supplied runId in step lookups/listing.
packages/world-local/src/storage/runs-storage.tsValidates runId before reading run JSON.
packages/world-local/src/storage/legacy.tsAdds local runId validation and switches legacy writes to contained path resolution.
packages/world-local/src/storage/hooks-storage.tsValidates hookId before reading hook JSON.
packages/world-local/src/storage/events-storage.tsAdds request-ID validation and containment checks for event/lock-path handling.
packages/world-local/src/storage.test.tsAdds storage-level regression tests for traversal attempts.
packages/world-local/src/fs.tsIntroduces centralized ID/path safety helpers and applies them in shared FS utilities.
packages/world-local/src/fs.test.tsAdds unit tests for ID validation, error behavior, and base-dir containment.
.changeset/world-local-path-traversal.mdDeclares the patch release note for @workflow/world-local.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadpackages/world-local/src/fs.ts Outdated
Comment threadpackages/world-local/src/storage/events-storage.ts Outdated
Comment threadpackages/world-local/src/streamer.ts
…ests
Addresses code review feedback on the path-traversal backport:
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
- Add streamer regression tests covering writeToStream, closeStream,
listStreamsByRunId, and getStreamChunks (the v4-shape surface that
this backport touches independently of main).
@TooTallNate
TooTallNate merged commit 5f50bbc into stableMay 22, 2026
86 of 91 checks passed
@TooTallNate
TooTallNate deleted the nathan/backport-1829-path-traversal branch May 22, 2026 20:28
TooTallNate added a commit that referenced this pull request May 22, 2026
* fix(world-local): tighten ID validation
Forward-port of code review fixes from #1920 (backport of #1829):
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
The streamer regression tests from #1920 are not forward-ported because
main's streamer surface differs (renamed methods, separate test
coverage) from stable's v4 shape.
* simplify changeset
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@TooTallNate@ijjk
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs - #1920

Merged
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal
May 22, 2026
Merged

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs#1920
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal

Conversation

@TooTallNate

Copy link
Copy Markdown
Member

Summary

Backport of #1829 (security fix) to the stable branch.

Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId, stream names, and tags) flowed directly into path.join() calls in @workflow/world-local, allowing a client to send values like ../../../package and cause the backend to read or write files outside the workflow data directory.

This adds a centralized validator (assertSafeEntityId) that rejects IDs which are empty, start with ., or contain path separators or NUL bytes, and applies it at every storage-layer entry point that composes IDs into filesystem paths.

Backport details

The cherry-pick applied cleanly except for two files where stable's pre-v5 shape diverged from main:

  • packages/world-local/src/storage/steps-storage.ts — Stable's steps.get() accepts an optional runId and looks it up via listJSONFiles when missing; main's signature requires runId. Resolution: assert stepId always, and only assert runId when it was supplied (the disk lookup only ever produces internal-derived runIds, so it can't be attacker-controlled).
  • packages/world-local/src/streamer.ts — Stable still has the v4 streamer interface (separate closeStream / listStreamsByRunId / getStreamChunks methods rather than main's renamed equivalents). The auto-merge produced a stray duplicate block that conflicted with stable's existing getStreamChunks chunk-walking loop. Resolution: kept stable's existing loop; threaded the assertSafeEntityId('runId', runId) call into stable's listStreamsByRunId. The other three call sites (listChunkFilesForStream, registerStreamForRun, plus the import) auto-merged correctly.

All 339 tests in packages/world-local pass, including the new path-traversal test cases (60 in fs.test.ts covering assertSafeEntityId, UnsafeEntityIdError, error truncation, etc.). Workspace pnpm typecheck is clean.

Test plan

cd packages/world-local && pnpm test
pnpm turbo build --filter @workflow/world-local
pnpm typecheck

)
* fix(world-local): prevent path traversal via request-supplied IDs
Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId,
stream names, and tags) flowed directly into path.join() calls, allowing a
client to send values like '../../../package' and cause the backend to read
or write files outside the workflow data directory.
Add a centralized validator (assertSafeEntityId) that rejects IDs which are
empty, start with '.', or contain path separators or NUL bytes. Apply it at
each storage-layer entry point that composes IDs into filesystem paths:
fs.taggedPath / readJSONWithFallback / paginatedFileSystemQuery, the runs /
steps / events / hooks storage methods, and the streamer.
* address review feedback
- UnsafeEntityIdError now extends WorkflowWorldError for consistency with
other storage-layer errors and the platform error-to-HTTP mapping.
- Add resolveWithinBase(basedir, ...segments) containment helper and
apply it at every taggedPath / readJSONWithFallback / .locks path
construction site in events-storage and legacy, so a forgotten
assertSafeEntityId at a future call site can't silently regress.
- Truncate attacker-controlled values in the error message.
- Drop unused assertSafeEntityIds helper and the unreachable typeof
check under the TS signature.
- Fix docstrings on assertSafeEntityId / taggedPath JSDoc example /
filePrefix validation comment to match what the code actually does.
- handleLegacyEvent now re-asserts runId locally so the invariant is
documented at the call site instead of implicitly inherited from
events.create.
---------
Co-authored-by: JJ Kasper <jj@jjsweb.site>
CopilotAI review requested due to automatic review settings May 4, 2026 19:58
@changeset-bot

changeset-botBot commented May 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0600f5f

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@workflow/world-localPatch
@workflow/cliPatch
@workflow/corePatch
@workflow/vitestPatch
@workflow/world-postgresPatch
workflowPatch
@workflow/world-testingPatch
@workflow/buildersPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actionsBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
❌ ▲ Vercel Production898367968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4403723614836

❌ Failed Tests

▲ Vercel Production (3 failed)

nextjs-webpack (1 failed):

  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R | 🔍 observability

nitro (1 failed):

  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09 | 🔍 observability

nuxt (1 failed):

  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0 | 🔍 observability
🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS8MGHFZ6KS45FVEW0XQX7V4
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS8MEN5F3KCSEK0QSW06CTT8
  • promiseRaceWorkflow | wrun_01KS8MESSXSM2C1353G8A5ZKNB
  • promiseAnyWorkflow | wrun_01KS8MEWB1AEWPZB0YTKJPYF5D
  • importedStepOnlyWorkflow | wrun_01KS8MGVXGWGZKAG56SZJ49K71
  • readableStreamWorkflow | wrun_01KS8MEYM1H7RRPMXEX8MQ3PHX
  • hookWorkflow | wrun_01KS8MFAQBXA9A3VFSDWYDHDWC
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS8MFJG7KZXNKDJNWDJ79Z88
  • webhookWorkflow | wrun_01KS8MFQDT9Y5CXXESREAWEHNW
  • sleepingWorkflow | wrun_01KS8MFY89KFYS10VK4TRNJT2P
  • parallelSleepWorkflow | wrun_01KS8MGDZ32T0NX5BB7Y77XF3Y
  • nullByteWorkflow | wrun_01KS8MGHE40E6ABNDA9E699V71
  • workflowAndStepMetadataWorkflow | wrun_01KS8MGM29HGDP86NM0FN49JGA
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS8MK2VEWW2YK1965TDPA1SP
  • fetchWorkflow | wrun_01KS8MKHF9QEHE5V3HQ28A74QS
  • promiseRaceStressTestWorkflow | wrun_01KS8MKN1TMEAPJTS92Y9ASHNQ
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS8MQ40N6R2PHEQ6YEC8KZS7
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS8MQGQ96G58SQ3C41MYMX56
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS8MRW8PNZ19JMHAG8VM59MY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS8MS2ETVR65YA5N1ENFP8X1
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS8MS4N6V6EERRYVVTY949TS
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS8MSVM5PMDAC29E0YVB07DV
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS8MT2HKAQ41FVAM91P2M8BK
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS8MTAC9C7QW3DTTP264TYS2
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS8MTH9G0JDXPSJA33041NT3
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS8MTREN07PM8ZSX64ZCXQBY
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS8MV0174CV1S586WDRMA532
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS8MVFAX6EJTRM8YC3ZVS9BB
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS8MVRVM9R89WWMRC7YK1X90
  • cancelRun - cancelling a running workflow | wrun_01KS8MVZX080BHGXNR2J43H8S5
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS8MW9D8MEMXTRE971ZC7NWJ
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS8MWQA4NBWBGVZ5FA5E169W
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS8MX7PW79NDPP3TSMQR87JY
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS8MXJ9QWW067NCK4YRV9NET
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS8MXSN3SN2YV62CQ6CMTQZR
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS8MXW5SF5Y9RT5WDMKY2F4K
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS8MXYARJCH4FXKT1NSQK98G

Details by Category

❌ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
❌ nextjs-webpack8512
❌ nitro8017
❌ nuxt8017
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run


Some E2E test jobs failed:

  • Vercel Prod: failure
  • Local Dev: success
  • Local Prod: success
  • Local Postgres: success
  • Windows: success

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backport of the world-local path-traversal fix from main to stable, adding centralized ID validation and applying it across filesystem-backed storage paths so request-supplied identifiers cannot escape the local workflow data directory.

Changes:

  • Added assertSafeEntityId, UnsafeEntityIdError, and resolveWithinBase in fs.ts to validate IDs and enforce path containment.
  • Threaded ID validation through runs, steps, events, hooks, legacy handling, and streamer storage paths.
  • Added regression tests for filesystem helpers and storage-layer traversal cases, plus a changeset for the patch release.

Reviewed changes

Copilot reviewed 10 out of 10 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
packages/world-local/src/streamer.tsValidates stream names/run IDs before building stream metadata and chunk paths.
packages/world-local/src/storage/steps-storage.tsValidates stepId and optional caller-supplied runId in step lookups/listing.
packages/world-local/src/storage/runs-storage.tsValidates runId before reading run JSON.
packages/world-local/src/storage/legacy.tsAdds local runId validation and switches legacy writes to contained path resolution.
packages/world-local/src/storage/hooks-storage.tsValidates hookId before reading hook JSON.
packages/world-local/src/storage/events-storage.tsAdds request-ID validation and containment checks for event/lock-path handling.
packages/world-local/src/storage.test.tsAdds storage-level regression tests for traversal attempts.
packages/world-local/src/fs.tsIntroduces centralized ID/path safety helpers and applies them in shared FS utilities.
packages/world-local/src/fs.test.tsAdds unit tests for ID validation, error behavior, and base-dir containment.
.changeset/world-local-path-traversal.mdDeclares the patch release note for @workflow/world-local.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadpackages/world-local/src/fs.ts Outdated
Comment threadpackages/world-local/src/storage/events-storage.ts Outdated
Comment threadpackages/world-local/src/streamer.ts
…ests
Addresses code review feedback on the path-traversal backport:
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
- Add streamer regression tests covering writeToStream, closeStream,
listStreamsByRunId, and getStreamChunks (the v4-shape surface that
this backport touches independently of main).
@TooTallNate
TooTallNate merged commit 5f50bbc into stableMay 22, 2026
86 of 91 checks passed
@TooTallNate
TooTallNate deleted the nathan/backport-1829-path-traversal branch May 22, 2026 20:28
TooTallNate added a commit that referenced this pull request May 22, 2026
* fix(world-local): tighten ID validation
Forward-port of code review fixes from #1920 (backport of #1829):
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
The streamer regression tests from #1920 are not forward-ported because
main's streamer surface differs (renamed methods, separate test
coverage) from stable's v4 shape.
* simplify changeset
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@TooTallNate@ijjk
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs - #1920

Merged
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal
May 22, 2026
Merged

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs#1920
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal

Conversation

@TooTallNate

Copy link
Copy Markdown
Member

Summary

Backport of #1829 (security fix) to the stable branch.

Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId, stream names, and tags) flowed directly into path.join() calls in @workflow/world-local, allowing a client to send values like ../../../package and cause the backend to read or write files outside the workflow data directory.

This adds a centralized validator (assertSafeEntityId) that rejects IDs which are empty, start with ., or contain path separators or NUL bytes, and applies it at every storage-layer entry point that composes IDs into filesystem paths.

Backport details

The cherry-pick applied cleanly except for two files where stable's pre-v5 shape diverged from main:

  • packages/world-local/src/storage/steps-storage.ts — Stable's steps.get() accepts an optional runId and looks it up via listJSONFiles when missing; main's signature requires runId. Resolution: assert stepId always, and only assert runId when it was supplied (the disk lookup only ever produces internal-derived runIds, so it can't be attacker-controlled).
  • packages/world-local/src/streamer.ts — Stable still has the v4 streamer interface (separate closeStream / listStreamsByRunId / getStreamChunks methods rather than main's renamed equivalents). The auto-merge produced a stray duplicate block that conflicted with stable's existing getStreamChunks chunk-walking loop. Resolution: kept stable's existing loop; threaded the assertSafeEntityId('runId', runId) call into stable's listStreamsByRunId. The other three call sites (listChunkFilesForStream, registerStreamForRun, plus the import) auto-merged correctly.

All 339 tests in packages/world-local pass, including the new path-traversal test cases (60 in fs.test.ts covering assertSafeEntityId, UnsafeEntityIdError, error truncation, etc.). Workspace pnpm typecheck is clean.

Test plan

cd packages/world-local && pnpm test
pnpm turbo build --filter @workflow/world-local
pnpm typecheck

)
* fix(world-local): prevent path traversal via request-supplied IDs
Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId,
stream names, and tags) flowed directly into path.join() calls, allowing a
client to send values like '../../../package' and cause the backend to read
or write files outside the workflow data directory.
Add a centralized validator (assertSafeEntityId) that rejects IDs which are
empty, start with '.', or contain path separators or NUL bytes. Apply it at
each storage-layer entry point that composes IDs into filesystem paths:
fs.taggedPath / readJSONWithFallback / paginatedFileSystemQuery, the runs /
steps / events / hooks storage methods, and the streamer.
* address review feedback
- UnsafeEntityIdError now extends WorkflowWorldError for consistency with
other storage-layer errors and the platform error-to-HTTP mapping.
- Add resolveWithinBase(basedir, ...segments) containment helper and
apply it at every taggedPath / readJSONWithFallback / .locks path
construction site in events-storage and legacy, so a forgotten
assertSafeEntityId at a future call site can't silently regress.
- Truncate attacker-controlled values in the error message.
- Drop unused assertSafeEntityIds helper and the unreachable typeof
check under the TS signature.
- Fix docstrings on assertSafeEntityId / taggedPath JSDoc example /
filePrefix validation comment to match what the code actually does.
- handleLegacyEvent now re-asserts runId locally so the invariant is
documented at the call site instead of implicitly inherited from
events.create.
---------
Co-authored-by: JJ Kasper <jj@jjsweb.site>
CopilotAI review requested due to automatic review settings May 4, 2026 19:58
@changeset-bot

changeset-botBot commented May 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0600f5f

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@workflow/world-localPatch
@workflow/cliPatch
@workflow/corePatch
@workflow/vitestPatch
@workflow/world-postgresPatch
workflowPatch
@workflow/world-testingPatch
@workflow/buildersPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actionsBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
❌ ▲ Vercel Production898367968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4403723614836

❌ Failed Tests

▲ Vercel Production (3 failed)

nextjs-webpack (1 failed):

  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R | 🔍 observability

nitro (1 failed):

  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09 | 🔍 observability

nuxt (1 failed):

  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0 | 🔍 observability
🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS8MGHFZ6KS45FVEW0XQX7V4
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS8MEN5F3KCSEK0QSW06CTT8
  • promiseRaceWorkflow | wrun_01KS8MESSXSM2C1353G8A5ZKNB
  • promiseAnyWorkflow | wrun_01KS8MEWB1AEWPZB0YTKJPYF5D
  • importedStepOnlyWorkflow | wrun_01KS8MGVXGWGZKAG56SZJ49K71
  • readableStreamWorkflow | wrun_01KS8MEYM1H7RRPMXEX8MQ3PHX
  • hookWorkflow | wrun_01KS8MFAQBXA9A3VFSDWYDHDWC
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS8MFJG7KZXNKDJNWDJ79Z88
  • webhookWorkflow | wrun_01KS8MFQDT9Y5CXXESREAWEHNW
  • sleepingWorkflow | wrun_01KS8MFY89KFYS10VK4TRNJT2P
  • parallelSleepWorkflow | wrun_01KS8MGDZ32T0NX5BB7Y77XF3Y
  • nullByteWorkflow | wrun_01KS8MGHE40E6ABNDA9E699V71
  • workflowAndStepMetadataWorkflow | wrun_01KS8MGM29HGDP86NM0FN49JGA
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS8MK2VEWW2YK1965TDPA1SP
  • fetchWorkflow | wrun_01KS8MKHF9QEHE5V3HQ28A74QS
  • promiseRaceStressTestWorkflow | wrun_01KS8MKN1TMEAPJTS92Y9ASHNQ
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS8MQ40N6R2PHEQ6YEC8KZS7
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS8MQGQ96G58SQ3C41MYMX56
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS8MRW8PNZ19JMHAG8VM59MY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS8MS2ETVR65YA5N1ENFP8X1
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS8MS4N6V6EERRYVVTY949TS
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS8MSVM5PMDAC29E0YVB07DV
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS8MT2HKAQ41FVAM91P2M8BK
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS8MTAC9C7QW3DTTP264TYS2
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS8MTH9G0JDXPSJA33041NT3
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS8MTREN07PM8ZSX64ZCXQBY
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS8MV0174CV1S586WDRMA532
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS8MVFAX6EJTRM8YC3ZVS9BB
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS8MVRVM9R89WWMRC7YK1X90
  • cancelRun - cancelling a running workflow | wrun_01KS8MVZX080BHGXNR2J43H8S5
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS8MW9D8MEMXTRE971ZC7NWJ
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS8MWQA4NBWBGVZ5FA5E169W
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS8MX7PW79NDPP3TSMQR87JY
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS8MXJ9QWW067NCK4YRV9NET
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS8MXSN3SN2YV62CQ6CMTQZR
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS8MXW5SF5Y9RT5WDMKY2F4K
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS8MXYARJCH4FXKT1NSQK98G

Details by Category

❌ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
❌ nextjs-webpack8512
❌ nitro8017
❌ nuxt8017
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run


Some E2E test jobs failed:

  • Vercel Prod: failure
  • Local Dev: success
  • Local Prod: success
  • Local Postgres: success
  • Windows: success

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backport of the world-local path-traversal fix from main to stable, adding centralized ID validation and applying it across filesystem-backed storage paths so request-supplied identifiers cannot escape the local workflow data directory.

Changes:

  • Added assertSafeEntityId, UnsafeEntityIdError, and resolveWithinBase in fs.ts to validate IDs and enforce path containment.
  • Threaded ID validation through runs, steps, events, hooks, legacy handling, and streamer storage paths.
  • Added regression tests for filesystem helpers and storage-layer traversal cases, plus a changeset for the patch release.

Reviewed changes

Copilot reviewed 10 out of 10 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
packages/world-local/src/streamer.tsValidates stream names/run IDs before building stream metadata and chunk paths.
packages/world-local/src/storage/steps-storage.tsValidates stepId and optional caller-supplied runId in step lookups/listing.
packages/world-local/src/storage/runs-storage.tsValidates runId before reading run JSON.
packages/world-local/src/storage/legacy.tsAdds local runId validation and switches legacy writes to contained path resolution.
packages/world-local/src/storage/hooks-storage.tsValidates hookId before reading hook JSON.
packages/world-local/src/storage/events-storage.tsAdds request-ID validation and containment checks for event/lock-path handling.
packages/world-local/src/storage.test.tsAdds storage-level regression tests for traversal attempts.
packages/world-local/src/fs.tsIntroduces centralized ID/path safety helpers and applies them in shared FS utilities.
packages/world-local/src/fs.test.tsAdds unit tests for ID validation, error behavior, and base-dir containment.
.changeset/world-local-path-traversal.mdDeclares the patch release note for @workflow/world-local.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadpackages/world-local/src/fs.ts Outdated
Comment threadpackages/world-local/src/storage/events-storage.ts Outdated
Comment threadpackages/world-local/src/streamer.ts
…ests
Addresses code review feedback on the path-traversal backport:
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
- Add streamer regression tests covering writeToStream, closeStream,
listStreamsByRunId, and getStreamChunks (the v4-shape surface that
this backport touches independently of main).
@TooTallNate
TooTallNate merged commit 5f50bbc into stableMay 22, 2026
86 of 91 checks passed
@TooTallNate
TooTallNate deleted the nathan/backport-1829-path-traversal branch May 22, 2026 20:28
TooTallNate added a commit that referenced this pull request May 22, 2026
* fix(world-local): tighten ID validation
Forward-port of code review fixes from #1920 (backport of #1829):
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
The streamer regression tests from #1920 are not forward-ported because
main's streamer surface differs (renamed methods, separate test
coverage) from stable's v4 shape.
* simplify changeset
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@TooTallNate@ijjk
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs - #1920

Merged
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal
May 22, 2026
Merged

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs#1920
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal

Conversation

@TooTallNate

Copy link
Copy Markdown
Member

Summary

Backport of #1829 (security fix) to the stable branch.

Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId, stream names, and tags) flowed directly into path.join() calls in @workflow/world-local, allowing a client to send values like ../../../package and cause the backend to read or write files outside the workflow data directory.

This adds a centralized validator (assertSafeEntityId) that rejects IDs which are empty, start with ., or contain path separators or NUL bytes, and applies it at every storage-layer entry point that composes IDs into filesystem paths.

Backport details

The cherry-pick applied cleanly except for two files where stable's pre-v5 shape diverged from main:

  • packages/world-local/src/storage/steps-storage.ts — Stable's steps.get() accepts an optional runId and looks it up via listJSONFiles when missing; main's signature requires runId. Resolution: assert stepId always, and only assert runId when it was supplied (the disk lookup only ever produces internal-derived runIds, so it can't be attacker-controlled).
  • packages/world-local/src/streamer.ts — Stable still has the v4 streamer interface (separate closeStream / listStreamsByRunId / getStreamChunks methods rather than main's renamed equivalents). The auto-merge produced a stray duplicate block that conflicted with stable's existing getStreamChunks chunk-walking loop. Resolution: kept stable's existing loop; threaded the assertSafeEntityId('runId', runId) call into stable's listStreamsByRunId. The other three call sites (listChunkFilesForStream, registerStreamForRun, plus the import) auto-merged correctly.

All 339 tests in packages/world-local pass, including the new path-traversal test cases (60 in fs.test.ts covering assertSafeEntityId, UnsafeEntityIdError, error truncation, etc.). Workspace pnpm typecheck is clean.

Test plan

cd packages/world-local && pnpm test
pnpm turbo build --filter @workflow/world-local
pnpm typecheck

)
* fix(world-local): prevent path traversal via request-supplied IDs
Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId,
stream names, and tags) flowed directly into path.join() calls, allowing a
client to send values like '../../../package' and cause the backend to read
or write files outside the workflow data directory.
Add a centralized validator (assertSafeEntityId) that rejects IDs which are
empty, start with '.', or contain path separators or NUL bytes. Apply it at
each storage-layer entry point that composes IDs into filesystem paths:
fs.taggedPath / readJSONWithFallback / paginatedFileSystemQuery, the runs /
steps / events / hooks storage methods, and the streamer.
* address review feedback
- UnsafeEntityIdError now extends WorkflowWorldError for consistency with
other storage-layer errors and the platform error-to-HTTP mapping.
- Add resolveWithinBase(basedir, ...segments) containment helper and
apply it at every taggedPath / readJSONWithFallback / .locks path
construction site in events-storage and legacy, so a forgotten
assertSafeEntityId at a future call site can't silently regress.
- Truncate attacker-controlled values in the error message.
- Drop unused assertSafeEntityIds helper and the unreachable typeof
check under the TS signature.
- Fix docstrings on assertSafeEntityId / taggedPath JSDoc example /
filePrefix validation comment to match what the code actually does.
- handleLegacyEvent now re-asserts runId locally so the invariant is
documented at the call site instead of implicitly inherited from
events.create.
---------
Co-authored-by: JJ Kasper <jj@jjsweb.site>
CopilotAI review requested due to automatic review settings May 4, 2026 19:58
@changeset-bot

changeset-botBot commented May 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0600f5f

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@workflow/world-localPatch
@workflow/cliPatch
@workflow/corePatch
@workflow/vitestPatch
@workflow/world-postgresPatch
workflowPatch
@workflow/world-testingPatch
@workflow/buildersPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actionsBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
❌ ▲ Vercel Production898367968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4403723614836

❌ Failed Tests

▲ Vercel Production (3 failed)

nextjs-webpack (1 failed):

  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R | 🔍 observability

nitro (1 failed):

  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09 | 🔍 observability

nuxt (1 failed):

  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0 | 🔍 observability
🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS8MGHFZ6KS45FVEW0XQX7V4
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS8MEN5F3KCSEK0QSW06CTT8
  • promiseRaceWorkflow | wrun_01KS8MESSXSM2C1353G8A5ZKNB
  • promiseAnyWorkflow | wrun_01KS8MEWB1AEWPZB0YTKJPYF5D
  • importedStepOnlyWorkflow | wrun_01KS8MGVXGWGZKAG56SZJ49K71
  • readableStreamWorkflow | wrun_01KS8MEYM1H7RRPMXEX8MQ3PHX
  • hookWorkflow | wrun_01KS8MFAQBXA9A3VFSDWYDHDWC
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS8MFJG7KZXNKDJNWDJ79Z88
  • webhookWorkflow | wrun_01KS8MFQDT9Y5CXXESREAWEHNW
  • sleepingWorkflow | wrun_01KS8MFY89KFYS10VK4TRNJT2P
  • parallelSleepWorkflow | wrun_01KS8MGDZ32T0NX5BB7Y77XF3Y
  • nullByteWorkflow | wrun_01KS8MGHE40E6ABNDA9E699V71
  • workflowAndStepMetadataWorkflow | wrun_01KS8MGM29HGDP86NM0FN49JGA
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS8MK2VEWW2YK1965TDPA1SP
  • fetchWorkflow | wrun_01KS8MKHF9QEHE5V3HQ28A74QS
  • promiseRaceStressTestWorkflow | wrun_01KS8MKN1TMEAPJTS92Y9ASHNQ
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS8MQ40N6R2PHEQ6YEC8KZS7
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS8MQGQ96G58SQ3C41MYMX56
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS8MRW8PNZ19JMHAG8VM59MY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS8MS2ETVR65YA5N1ENFP8X1
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS8MS4N6V6EERRYVVTY949TS
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS8MSVM5PMDAC29E0YVB07DV
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS8MT2HKAQ41FVAM91P2M8BK
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS8MTAC9C7QW3DTTP264TYS2
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS8MTH9G0JDXPSJA33041NT3
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS8MTREN07PM8ZSX64ZCXQBY
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS8MV0174CV1S586WDRMA532
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS8MVFAX6EJTRM8YC3ZVS9BB
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS8MVRVM9R89WWMRC7YK1X90
  • cancelRun - cancelling a running workflow | wrun_01KS8MVZX080BHGXNR2J43H8S5
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS8MW9D8MEMXTRE971ZC7NWJ
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS8MWQA4NBWBGVZ5FA5E169W
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS8MX7PW79NDPP3TSMQR87JY
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS8MXJ9QWW067NCK4YRV9NET
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS8MXSN3SN2YV62CQ6CMTQZR
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS8MXW5SF5Y9RT5WDMKY2F4K
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS8MXYARJCH4FXKT1NSQK98G

Details by Category

❌ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
❌ nextjs-webpack8512
❌ nitro8017
❌ nuxt8017
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run


Some E2E test jobs failed:

  • Vercel Prod: failure
  • Local Dev: success
  • Local Prod: success
  • Local Postgres: success
  • Windows: success

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backport of the world-local path-traversal fix from main to stable, adding centralized ID validation and applying it across filesystem-backed storage paths so request-supplied identifiers cannot escape the local workflow data directory.

Changes:

  • Added assertSafeEntityId, UnsafeEntityIdError, and resolveWithinBase in fs.ts to validate IDs and enforce path containment.
  • Threaded ID validation through runs, steps, events, hooks, legacy handling, and streamer storage paths.
  • Added regression tests for filesystem helpers and storage-layer traversal cases, plus a changeset for the patch release.

Reviewed changes

Copilot reviewed 10 out of 10 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
packages/world-local/src/streamer.tsValidates stream names/run IDs before building stream metadata and chunk paths.
packages/world-local/src/storage/steps-storage.tsValidates stepId and optional caller-supplied runId in step lookups/listing.
packages/world-local/src/storage/runs-storage.tsValidates runId before reading run JSON.
packages/world-local/src/storage/legacy.tsAdds local runId validation and switches legacy writes to contained path resolution.
packages/world-local/src/storage/hooks-storage.tsValidates hookId before reading hook JSON.
packages/world-local/src/storage/events-storage.tsAdds request-ID validation and containment checks for event/lock-path handling.
packages/world-local/src/storage.test.tsAdds storage-level regression tests for traversal attempts.
packages/world-local/src/fs.tsIntroduces centralized ID/path safety helpers and applies them in shared FS utilities.
packages/world-local/src/fs.test.tsAdds unit tests for ID validation, error behavior, and base-dir containment.
.changeset/world-local-path-traversal.mdDeclares the patch release note for @workflow/world-local.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadpackages/world-local/src/fs.ts Outdated
Comment threadpackages/world-local/src/storage/events-storage.ts Outdated
Comment threadpackages/world-local/src/streamer.ts
…ests
Addresses code review feedback on the path-traversal backport:
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
- Add streamer regression tests covering writeToStream, closeStream,
listStreamsByRunId, and getStreamChunks (the v4-shape surface that
this backport touches independently of main).
@TooTallNate
TooTallNate merged commit 5f50bbc into stableMay 22, 2026
86 of 91 checks passed
@TooTallNate
TooTallNate deleted the nathan/backport-1829-path-traversal branch May 22, 2026 20:28
TooTallNate added a commit that referenced this pull request May 22, 2026
* fix(world-local): tighten ID validation
Forward-port of code review fixes from #1920 (backport of #1829):
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
The streamer regression tests from #1920 are not forward-ported because
main's streamer surface differs (renamed methods, separate test
coverage) from stable's v4 shape.
* simplify changeset
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@TooTallNate@ijjk
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs - #1920

Merged
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal
May 22, 2026
Merged

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs#1920
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal

Conversation

@TooTallNate

Copy link
Copy Markdown
Member

Summary

Backport of #1829 (security fix) to the stable branch.

Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId, stream names, and tags) flowed directly into path.join() calls in @workflow/world-local, allowing a client to send values like ../../../package and cause the backend to read or write files outside the workflow data directory.

This adds a centralized validator (assertSafeEntityId) that rejects IDs which are empty, start with ., or contain path separators or NUL bytes, and applies it at every storage-layer entry point that composes IDs into filesystem paths.

Backport details

The cherry-pick applied cleanly except for two files where stable's pre-v5 shape diverged from main:

  • packages/world-local/src/storage/steps-storage.ts — Stable's steps.get() accepts an optional runId and looks it up via listJSONFiles when missing; main's signature requires runId. Resolution: assert stepId always, and only assert runId when it was supplied (the disk lookup only ever produces internal-derived runIds, so it can't be attacker-controlled).
  • packages/world-local/src/streamer.ts — Stable still has the v4 streamer interface (separate closeStream / listStreamsByRunId / getStreamChunks methods rather than main's renamed equivalents). The auto-merge produced a stray duplicate block that conflicted with stable's existing getStreamChunks chunk-walking loop. Resolution: kept stable's existing loop; threaded the assertSafeEntityId('runId', runId) call into stable's listStreamsByRunId. The other three call sites (listChunkFilesForStream, registerStreamForRun, plus the import) auto-merged correctly.

All 339 tests in packages/world-local pass, including the new path-traversal test cases (60 in fs.test.ts covering assertSafeEntityId, UnsafeEntityIdError, error truncation, etc.). Workspace pnpm typecheck is clean.

Test plan

cd packages/world-local && pnpm test
pnpm turbo build --filter @workflow/world-local
pnpm typecheck

)
* fix(world-local): prevent path traversal via request-supplied IDs
Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId,
stream names, and tags) flowed directly into path.join() calls, allowing a
client to send values like '../../../package' and cause the backend to read
or write files outside the workflow data directory.
Add a centralized validator (assertSafeEntityId) that rejects IDs which are
empty, start with '.', or contain path separators or NUL bytes. Apply it at
each storage-layer entry point that composes IDs into filesystem paths:
fs.taggedPath / readJSONWithFallback / paginatedFileSystemQuery, the runs /
steps / events / hooks storage methods, and the streamer.
* address review feedback
- UnsafeEntityIdError now extends WorkflowWorldError for consistency with
other storage-layer errors and the platform error-to-HTTP mapping.
- Add resolveWithinBase(basedir, ...segments) containment helper and
apply it at every taggedPath / readJSONWithFallback / .locks path
construction site in events-storage and legacy, so a forgotten
assertSafeEntityId at a future call site can't silently regress.
- Truncate attacker-controlled values in the error message.
- Drop unused assertSafeEntityIds helper and the unreachable typeof
check under the TS signature.
- Fix docstrings on assertSafeEntityId / taggedPath JSDoc example /
filePrefix validation comment to match what the code actually does.
- handleLegacyEvent now re-asserts runId locally so the invariant is
documented at the call site instead of implicitly inherited from
events.create.
---------
Co-authored-by: JJ Kasper <jj@jjsweb.site>
CopilotAI review requested due to automatic review settings May 4, 2026 19:58
@changeset-bot

changeset-botBot commented May 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0600f5f

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@workflow/world-localPatch
@workflow/cliPatch
@workflow/corePatch
@workflow/vitestPatch
@workflow/world-postgresPatch
workflowPatch
@workflow/world-testingPatch
@workflow/buildersPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actionsBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
❌ ▲ Vercel Production898367968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4403723614836

❌ Failed Tests

▲ Vercel Production (3 failed)

nextjs-webpack (1 failed):

  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R | 🔍 observability

nitro (1 failed):

  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09 | 🔍 observability

nuxt (1 failed):

  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0 | 🔍 observability
🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS8MGHFZ6KS45FVEW0XQX7V4
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS8MEN5F3KCSEK0QSW06CTT8
  • promiseRaceWorkflow | wrun_01KS8MESSXSM2C1353G8A5ZKNB
  • promiseAnyWorkflow | wrun_01KS8MEWB1AEWPZB0YTKJPYF5D
  • importedStepOnlyWorkflow | wrun_01KS8MGVXGWGZKAG56SZJ49K71
  • readableStreamWorkflow | wrun_01KS8MEYM1H7RRPMXEX8MQ3PHX
  • hookWorkflow | wrun_01KS8MFAQBXA9A3VFSDWYDHDWC
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS8MFJG7KZXNKDJNWDJ79Z88
  • webhookWorkflow | wrun_01KS8MFQDT9Y5CXXESREAWEHNW
  • sleepingWorkflow | wrun_01KS8MFY89KFYS10VK4TRNJT2P
  • parallelSleepWorkflow | wrun_01KS8MGDZ32T0NX5BB7Y77XF3Y
  • nullByteWorkflow | wrun_01KS8MGHE40E6ABNDA9E699V71
  • workflowAndStepMetadataWorkflow | wrun_01KS8MGM29HGDP86NM0FN49JGA
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS8MK2VEWW2YK1965TDPA1SP
  • fetchWorkflow | wrun_01KS8MKHF9QEHE5V3HQ28A74QS
  • promiseRaceStressTestWorkflow | wrun_01KS8MKN1TMEAPJTS92Y9ASHNQ
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS8MQ40N6R2PHEQ6YEC8KZS7
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS8MQGQ96G58SQ3C41MYMX56
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS8MRW8PNZ19JMHAG8VM59MY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS8MS2ETVR65YA5N1ENFP8X1
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS8MS4N6V6EERRYVVTY949TS
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS8MSVM5PMDAC29E0YVB07DV
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS8MT2HKAQ41FVAM91P2M8BK
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS8MTAC9C7QW3DTTP264TYS2
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS8MTH9G0JDXPSJA33041NT3
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS8MTREN07PM8ZSX64ZCXQBY
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS8MV0174CV1S586WDRMA532
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS8MVFAX6EJTRM8YC3ZVS9BB
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS8MVRVM9R89WWMRC7YK1X90
  • cancelRun - cancelling a running workflow | wrun_01KS8MVZX080BHGXNR2J43H8S5
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS8MW9D8MEMXTRE971ZC7NWJ
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS8MWQA4NBWBGVZ5FA5E169W
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS8MX7PW79NDPP3TSMQR87JY
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS8MXJ9QWW067NCK4YRV9NET
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS8MXSN3SN2YV62CQ6CMTQZR
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS8MXW5SF5Y9RT5WDMKY2F4K
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS8MXYARJCH4FXKT1NSQK98G

Details by Category

❌ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
❌ nextjs-webpack8512
❌ nitro8017
❌ nuxt8017
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run


Some E2E test jobs failed:

  • Vercel Prod: failure
  • Local Dev: success
  • Local Prod: success
  • Local Postgres: success
  • Windows: success

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backport of the world-local path-traversal fix from main to stable, adding centralized ID validation and applying it across filesystem-backed storage paths so request-supplied identifiers cannot escape the local workflow data directory.

Changes:

  • Added assertSafeEntityId, UnsafeEntityIdError, and resolveWithinBase in fs.ts to validate IDs and enforce path containment.
  • Threaded ID validation through runs, steps, events, hooks, legacy handling, and streamer storage paths.
  • Added regression tests for filesystem helpers and storage-layer traversal cases, plus a changeset for the patch release.

Reviewed changes

Copilot reviewed 10 out of 10 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
packages/world-local/src/streamer.tsValidates stream names/run IDs before building stream metadata and chunk paths.
packages/world-local/src/storage/steps-storage.tsValidates stepId and optional caller-supplied runId in step lookups/listing.
packages/world-local/src/storage/runs-storage.tsValidates runId before reading run JSON.
packages/world-local/src/storage/legacy.tsAdds local runId validation and switches legacy writes to contained path resolution.
packages/world-local/src/storage/hooks-storage.tsValidates hookId before reading hook JSON.
packages/world-local/src/storage/events-storage.tsAdds request-ID validation and containment checks for event/lock-path handling.
packages/world-local/src/storage.test.tsAdds storage-level regression tests for traversal attempts.
packages/world-local/src/fs.tsIntroduces centralized ID/path safety helpers and applies them in shared FS utilities.
packages/world-local/src/fs.test.tsAdds unit tests for ID validation, error behavior, and base-dir containment.
.changeset/world-local-path-traversal.mdDeclares the patch release note for @workflow/world-local.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadpackages/world-local/src/fs.ts Outdated
Comment threadpackages/world-local/src/storage/events-storage.ts Outdated
Comment threadpackages/world-local/src/streamer.ts
…ests
Addresses code review feedback on the path-traversal backport:
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
- Add streamer regression tests covering writeToStream, closeStream,
listStreamsByRunId, and getStreamChunks (the v4-shape surface that
this backport touches independently of main).
@TooTallNate
TooTallNate merged commit 5f50bbc into stableMay 22, 2026
86 of 91 checks passed
@TooTallNate
TooTallNate deleted the nathan/backport-1829-path-traversal branch May 22, 2026 20:28
TooTallNate added a commit that referenced this pull request May 22, 2026
* fix(world-local): tighten ID validation
Forward-port of code review fixes from #1920 (backport of #1829):
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
The streamer regression tests from #1920 are not forward-ported because
main's streamer surface differs (renamed methods, separate test
coverage) from stable's v4 shape.
* simplify changeset
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@TooTallNate@ijjk
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs - #1920

Merged
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal
May 22, 2026
Merged

Backport #1829: fix(world-local): prevent path traversal via request-supplied IDs#1920
TooTallNate merged 3 commits into
stablefrom
nathan/backport-1829-path-traversal

Conversation

@TooTallNate

Copy link
Copy Markdown
Member

Summary

Backport of #1829 (security fix) to the stable branch.

Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId, stream names, and tags) flowed directly into path.join() calls in @workflow/world-local, allowing a client to send values like ../../../package and cause the backend to read or write files outside the workflow data directory.

This adds a centralized validator (assertSafeEntityId) that rejects IDs which are empty, start with ., or contain path separators or NUL bytes, and applies it at every storage-layer entry point that composes IDs into filesystem paths.

Backport details

The cherry-pick applied cleanly except for two files where stable's pre-v5 shape diverged from main:

  • packages/world-local/src/storage/steps-storage.ts — Stable's steps.get() accepts an optional runId and looks it up via listJSONFiles when missing; main's signature requires runId. Resolution: assert stepId always, and only assert runId when it was supplied (the disk lookup only ever produces internal-derived runIds, so it can't be attacker-controlled).
  • packages/world-local/src/streamer.ts — Stable still has the v4 streamer interface (separate closeStream / listStreamsByRunId / getStreamChunks methods rather than main's renamed equivalents). The auto-merge produced a stray duplicate block that conflicted with stable's existing getStreamChunks chunk-walking loop. Resolution: kept stable's existing loop; threaded the assertSafeEntityId('runId', runId) call into stable's listStreamsByRunId. The other three call sites (listChunkFilesForStream, registerStreamForRun, plus the import) auto-merged correctly.

All 339 tests in packages/world-local pass, including the new path-traversal test cases (60 in fs.test.ts covering assertSafeEntityId, UnsafeEntityIdError, error truncation, etc.). Workspace pnpm typecheck is clean.

Test plan

cd packages/world-local && pnpm test
pnpm turbo build --filter @workflow/world-local
pnpm typecheck

)
* fix(world-local): prevent path traversal via request-supplied IDs
Request-supplied identifiers (runId, eventId, stepId, hookId, correlationId,
stream names, and tags) flowed directly into path.join() calls, allowing a
client to send values like '../../../package' and cause the backend to read
or write files outside the workflow data directory.
Add a centralized validator (assertSafeEntityId) that rejects IDs which are
empty, start with '.', or contain path separators or NUL bytes. Apply it at
each storage-layer entry point that composes IDs into filesystem paths:
fs.taggedPath / readJSONWithFallback / paginatedFileSystemQuery, the runs /
steps / events / hooks storage methods, and the streamer.
* address review feedback
- UnsafeEntityIdError now extends WorkflowWorldError for consistency with
other storage-layer errors and the platform error-to-HTTP mapping.
- Add resolveWithinBase(basedir, ...segments) containment helper and
apply it at every taggedPath / readJSONWithFallback / .locks path
construction site in events-storage and legacy, so a forgotten
assertSafeEntityId at a future call site can't silently regress.
- Truncate attacker-controlled values in the error message.
- Drop unused assertSafeEntityIds helper and the unreachable typeof
check under the TS signature.
- Fix docstrings on assertSafeEntityId / taggedPath JSDoc example /
filePrefix validation comment to match what the code actually does.
- handleLegacyEvent now re-asserts runId locally so the invariant is
documented at the call site instead of implicitly inherited from
events.create.
---------
Co-authored-by: JJ Kasper <jj@jjsweb.site>
CopilotAI review requested due to automatic review settings May 4, 2026 19:58
@changeset-bot

changeset-botBot commented May 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0600f5f

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@workflow/world-localPatch
@workflow/cliPatch
@workflow/corePatch
@workflow/vitestPatch
@workflow/world-postgresPatch
workflowPatch
@workflow/world-testingPatch
@workflow/buildersPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actionsBot commented May 4, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
❌ ▲ Vercel Production898367968
✅ 💻 Local Development9700861056
✅ 📦 Local Production9700861056
✅ 🐘 Local Postgres9700861056
✅ 🪟 Windows880088
❌ 🌍 Community Worlds1569084
✅ 📋 Other492036528
Total4403723614836

❌ Failed Tests

▲ Vercel Production (3 failed)

nextjs-webpack (1 failed):

  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R | 🔍 observability

nitro (1 failed):

  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09 | 🔍 observability

nuxt (1 failed):

  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0 | 🔍 observability
🌍 Community Worlds (69 failed)

mongodb-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

redis-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso-dev (1 failed):

  • dev e2e should rebuild on imported step dependency change

turso (66 failed):

  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • addTenWorkflow | wrun_01KS8MEE7VXWE4GVDVJKEN05WJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KS8MGHFZ6KS45FVEW0XQX7V4
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KS8MEN5F3KCSEK0QSW06CTT8
  • promiseRaceWorkflow | wrun_01KS8MESSXSM2C1353G8A5ZKNB
  • promiseAnyWorkflow | wrun_01KS8MEWB1AEWPZB0YTKJPYF5D
  • importedStepOnlyWorkflow | wrun_01KS8MGVXGWGZKAG56SZJ49K71
  • readableStreamWorkflow | wrun_01KS8MEYM1H7RRPMXEX8MQ3PHX
  • hookWorkflow | wrun_01KS8MFAQBXA9A3VFSDWYDHDWC
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KS8MFJG7KZXNKDJNWDJ79Z88
  • webhookWorkflow | wrun_01KS8MFQDT9Y5CXXESREAWEHNW
  • sleepingWorkflow | wrun_01KS8MFY89KFYS10VK4TRNJT2P
  • parallelSleepWorkflow | wrun_01KS8MGDZ32T0NX5BB7Y77XF3Y
  • nullByteWorkflow | wrun_01KS8MGHE40E6ABNDA9E699V71
  • workflowAndStepMetadataWorkflow | wrun_01KS8MGM29HGDP86NM0FN49JGA
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KS8MK2VEWW2YK1965TDPA1SP
  • fetchWorkflow | wrun_01KS8MKHF9QEHE5V3HQ28A74QS
  • promiseRaceStressTestWorkflow | wrun_01KS8MKN1TMEAPJTS92Y9ASHNQ
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KS8MQ40N6R2PHEQ6YEC8KZS7
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KS8MQGQ96G58SQ3C41MYMX56
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KS8MR17EKJW88CTMM5RXBC8R
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KS8MRJ7SXRRKPM9RE3SWMR09
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KS8MRW8PNZ19JMHAG8VM59MY
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KS8MS2ETVR65YA5N1ENFP8X1
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KS8MS4N6V6EERRYVVTY949TS
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KS8MSNEDSNN9PHADPRZ47XY0
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KS8MSVM5PMDAC29E0YVB07DV
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KS8MT2HKAQ41FVAM91P2M8BK
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KS8MTAC9C7QW3DTTP264TYS2
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KS8MTH9G0JDXPSJA33041NT3
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KS8MTREN07PM8ZSX64ZCXQBY
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KS8MV0174CV1S586WDRMA532
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KS8MVFAX6EJTRM8YC3ZVS9BB
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KS8MVRVM9R89WWMRC7YK1X90
  • cancelRun - cancelling a running workflow | wrun_01KS8MVZX080BHGXNR2J43H8S5
  • cancelRun via CLI - cancelling a running workflow | wrun_01KS8MW9D8MEMXTRE971ZC7NWJ
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KS8MWQA4NBWBGVZ5FA5E169W
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KS8MX7PW79NDPP3TSMQR87JY
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KS8MXJ9QWW067NCK4YRV9NET
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KS8MXSN3SN2YV62CQ6CMTQZR
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KS8MXW5SF5Y9RT5WDMKY2F4K
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KS8MXYARJCH4FXKT1NSQK98G

Details by Category

❌ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro8107
✅ example8107
✅ express8107
✅ fastify8107
✅ hono8107
✅ nextjs-turbopack8602
❌ nextjs-webpack8512
❌ nitro8017
❌ nuxt8017
✅ sveltekit8107
✅ vite8107
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable8206
✅ express-stable8206
✅ fastify-stable8206
✅ hono-stable8206
✅ nextjs-turbopack-canary69019
✅ nextjs-turbopack-stable8800
✅ nextjs-webpack-canary69019
✅ nextjs-webpack-stable8800
✅ nitro-stable8206
✅ nuxt-stable8206
✅ sveltekit-stable8206
✅ vite-stable8206
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack8800
❌ 🌍 Community Worlds
AppPassedFailedSkipped
❌ mongodb-dev410
❌ redis-dev410
❌ turso-dev410
❌ turso3660
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable8206
✅ e2e-local-dev-tanstack-start-stable8206
✅ e2e-local-postgres-nest-stable8206
✅ e2e-local-postgres-tanstack-start-stable8206
✅ e2e-local-prod-nest-stable8206
✅ e2e-local-prod-tanstack-start-stable8206

📋 View full workflow run


Some E2E test jobs failed:

  • Vercel Prod: failure
  • Local Dev: success
  • Local Prod: success
  • Local Postgres: success
  • Windows: success

Check the workflow run for details.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backport of the world-local path-traversal fix from main to stable, adding centralized ID validation and applying it across filesystem-backed storage paths so request-supplied identifiers cannot escape the local workflow data directory.

Changes:

  • Added assertSafeEntityId, UnsafeEntityIdError, and resolveWithinBase in fs.ts to validate IDs and enforce path containment.
  • Threaded ID validation through runs, steps, events, hooks, legacy handling, and streamer storage paths.
  • Added regression tests for filesystem helpers and storage-layer traversal cases, plus a changeset for the patch release.

Reviewed changes

Copilot reviewed 10 out of 10 changed files in this pull request and generated 3 comments.

Show a summary per file
FileDescription
packages/world-local/src/streamer.tsValidates stream names/run IDs before building stream metadata and chunk paths.
packages/world-local/src/storage/steps-storage.tsValidates stepId and optional caller-supplied runId in step lookups/listing.
packages/world-local/src/storage/runs-storage.tsValidates runId before reading run JSON.
packages/world-local/src/storage/legacy.tsAdds local runId validation and switches legacy writes to contained path resolution.
packages/world-local/src/storage/hooks-storage.tsValidates hookId before reading hook JSON.
packages/world-local/src/storage/events-storage.tsAdds request-ID validation and containment checks for event/lock-path handling.
packages/world-local/src/storage.test.tsAdds storage-level regression tests for traversal attempts.
packages/world-local/src/fs.tsIntroduces centralized ID/path safety helpers and applies them in shared FS utilities.
packages/world-local/src/fs.test.tsAdds unit tests for ID validation, error behavior, and base-dir containment.
.changeset/world-local-path-traversal.mdDeclares the patch release note for @workflow/world-local.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadpackages/world-local/src/fs.ts Outdated
Comment threadpackages/world-local/src/storage/events-storage.ts Outdated
Comment threadpackages/world-local/src/streamer.ts
…ests
Addresses code review feedback on the path-traversal backport:
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
- Add streamer regression tests covering writeToStream, closeStream,
listStreamsByRunId, and getStreamChunks (the v4-shape surface that
this backport touches independently of main).
@TooTallNate
TooTallNate merged commit 5f50bbc into stableMay 22, 2026
86 of 91 checks passed
@TooTallNate
TooTallNate deleted the nathan/backport-1829-path-traversal branch May 22, 2026 20:28
TooTallNate added a commit that referenced this pull request May 22, 2026
* fix(world-local): tighten ID validation
Forward-port of code review fixes from #1920 (backport of #1829):
- Reject dots inside entity IDs in `assertSafeEntityId`. Internal IDs
(ULIDs, step_N, etc.) never contain dots, but `stripTag()` /
`getObjectCreatedAt()` strip a trailing `.[tag]` suffix from filenames,
so a request-supplied runId like `wrun_123.foo` would be silently
mangled during listing/pagination.
- Reject empty `correlationId` on events that include one. The event
schemas only require `z.string()`, so without this check a
step_created / hook_created / wait_created request with
`correlationId: ''` would silently be written under a malformed
composite key like `${runId}-`.
The streamer regression tests from #1920 are not forward-ported because
main's streamer surface differs (renamed methods, separate test
coverage) from stable's v4 shape.
* simplify changeset
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@TooTallNate@ijjk