Skip to content

fix: isolate evidence storage filenames - #65

Merged
Notyet1307 merged 1 commit into
mainfrom
fix/sas-202-evidence-paths
Sep 8, 2026
Merged

fix: isolate evidence storage filenames#65
Notyet1307 merged 1 commit into
mainfrom
fix/sas-202-evidence-paths

Conversation

@Notyet1307

Copy link
Copy Markdown
Owner

Summary

  • keep client-visible Evidence IDs in record contents only
  • use server-generated safe storage filenames for temporary and final paths
  • retain loading compatibility with existing logical-ID filenames

This closes the two CodeQL uncontrolled-path findings reported on PR #64.

Verification

  • go test ./internal/store/file ./internal/httpapi
  • git diff --check

@Notyet1307
Notyet1307 merged commit 19a7d16 into main Sep 8, 2026
4 checks passed
@Notyet1307
Notyet1307 deleted the fix/sas-202-evidence-paths branch September 8, 2026 18:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant