mirror of
https://github.com/projectsend/projectsend.git
synced 2026-10-06 21:32:48 +00:00
1e34773ad3
The orphan check compared the path it was given with the paths file rows hold, but Flysystem rewrites a path before it touches storage: "./a/b", "a/./b", "a//b", "/a/b", "a\b" and "a/x/../b" all become "a/b". Any of them made a file somebody owns look like an orphan, so deleting it removed their bytes without delete_others_files, and importing it put a second row on them. The same spellings walked past the exclusion of derived-artifact folders. isOrphan(), which import and delete both go through, now refuses a path the normalizer would change or rejects outright. The scan only offers paths as storage lists them, so nothing it sends is affected. GHSA-pv88-7863-5hwq