Skip to content

[codex] fix: restrict graph commands to graphify-out#363

Open
aa-matsunari wants to merge 1 commit intosafishamsi:v4from
aa-matsunari:codex/apply-graph-path-guards
Open

[codex] fix: restrict graph commands to graphify-out#363
aa-matsunari wants to merge 1 commit intosafishamsi:v4from
aa-matsunari:codex/apply-graph-path-guards

Conversation

@aa-matsunari
Copy link
Copy Markdown

Summary

  • apply validate_graph_path to CLI graph commands and MCP graph loading
  • add regressions for blocked paths outside graphify-out

Changed files

  • graphify/main.py
  • graphify/serve.py
  • tests/test_serve.py
  • tests/test_pipeline.py

Impact

  • prevents graph query tooling from reading arbitrary JSON files outside the project graph directory

Tests

  • /private/tmp/graphify-review/.venv/bin/python -m pytest /private/tmp/graphify-review-pr6/tests/test_serve.py /private/tmp/graphify-review-pr6/tests/test_pipeline.py

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant