From 05bd7089f3ed5d6878c7321e51f74a481c11f583 Mon Sep 17 00:00:00 2001 From: Lex Christopherson Date: Wed, 18 Mar 2026 11:15:33 -0600 Subject: [PATCH] fix: broaden unit-runtime path sanitization to strip all unsafe characters Co-Authored-By: Claude Opus 4.6 (1M context) --- src/resources/extensions/gsd/unit-runtime.ts | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/resources/extensions/gsd/unit-runtime.ts b/src/resources/extensions/gsd/unit-runtime.ts index 8384ea401..cb4fab2cc 100644 --- a/src/resources/extensions/gsd/unit-runtime.ts +++ b/src/resources/extensions/gsd/unit-runtime.ts @@ -51,8 +51,8 @@ function runtimeDir(basePath: string): string { } function runtimePath(basePath: string, unitType: string, unitId: string): string { - const sanitizedUnitType = unitType.replace(/[\/]/g, "-"); - const sanitizedUnitId = unitId.replace(/[\/]/g, "-"); + const sanitizedUnitType = unitType.replace(/[^a-zA-Z0-9._-]+/g, "-"); + const sanitizedUnitId = unitId.replace(/[^a-zA-Z0-9._-]+/g, "-"); return join(runtimeDir(basePath), `${sanitizedUnitType}-${sanitizedUnitId}.json`); }