Skip to content

[P0][static] define shell quoting helper for static file checks #63

Description

@redpeacock78

Summary

core/static.awk calls _shellquote(full) when checking files under public/, but the core utility layer does not define _shellquote. As written, static file fallback can fail at runtime as soon as a non-routed GET/HEAD path reaches serve_static().

Evidence

  • core/static.awk: cmd = "test -f " _shellquote(full) ... inside serve_static().
  • core/util.awk: shared utility helpers define string/log/time helpers but no _shellquote helper.
  • core/mailbox.awk has mailbox::shell_quote(), but that is namespaced and not the _shellquote() used by static serving.

Impact

Static assets become fragile or unusable in the default 404 fallback path. This also breaks docs/examples that expect public/ files to be served automatically.

Suggested fix

  • Add a core-level _shellquote() helper, or rename the static call to an existing shared helper.
  • Add unit tests for serve_static() with readable, missing, unsafe, and quoted paths.
  • Add an e2e smoke test for serving public/app.css or similar.

Acceptance criteria

  • GET /some-existing-static-file works without undefined-function errors.
  • Paths with spaces or shell-sensitive characters are safely quoted.
  • Path traversal attempts still return 404/400-style failure instead of reading outside public/.

Priority: P0
Area: static/runtime
Type: bug

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions