Skip to content

fix(tracking): validate app ids in the local tracking client - #946

Open
elijahbenizzy wants to merge 1 commit into
mainfrom
fix/tracking-client-identifier-validation
Open

elijahbenizzy wants to merge 1 commit into
mainfrom
fix/tracking-client-identifier-validation

Conversation

@elijahbenizzy

Copy link
Copy Markdown
Contributor

LocalTrackingClient validated project names but not app_id, even though both become directory names under storage_dir. This change applies one rule to both (letters, digits, _, -, ., :; non-empty; not ./..; at most 255 chars) and adds a containment check on every path the client builds, so a malformed id fails at ApplicationBuilder.build() rather than producing files in unexpected places.

Side effects: project names may now contain .; the project-name error message is shorter. The validation helper lives in burr/tracking/common/identifiers.py so the tracking server can share it.

The local tracking client turned app ids (and the parent app ids used
for fork/spawn links) straight into directory names under the storage
directory. Apply the rule the project name already used -- letters,
digits, '_', '-', ':' and '.', non-empty, not '.' or '..', at most 255
characters -- to every identifier that becomes a path, and check that
joined paths stay inside the storage directory. The rule lives in
burr.tracking.common.identifiers so the server side can share it.

Errors surface as ValueError from ApplicationBuilder.build().

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/tracking Telemetry, tracing, OpenTelemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant