Skip to content

Allow the repository image symlink in previews - #346

Closed
Blargian wants to merge 1 commit into
mainfrom
codex/allow-repository-image-symlink
Closed

Allow the repository image symlink in previews#346
Blargian wants to merge 1 commit into
mainfrom
codex/allow-repository-image-symlink

Conversation

@Blargian

@Blargian Blargian commented Sep 9, 2026

Copy link
Copy Markdown
Member

The CI preview guard rejected the repository's intentional public/images../images link before Vercel could build PR #345. Allow only that exact repository-contained path and target while continuing to reject every other symbolic link.

Related: #345

Validated that the existing image link passes, an additional unapproved link fails, the workflow parses correctly, and the diff has no whitespace errors.

Changelog category (leave one):

  • CI Fix or Improvement (changelog entry is not required)

Changelog entry (a user-readable short description of the changes that goes into CHANGELOG.md):

Not applicable.

@Blargian

Blargian commented Sep 9, 2026

Copy link
Copy Markdown
Member Author

Moved this fix directly to #345 as requested.

@Blargian Blargian closed this Sep 9, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 3ebed95. Configure here.

target="$(readlink "$symlink")"
if [[ "$relative_path" == "public/images" && "$target" == "../images" ]]; then
continue
fi

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Allowlist misses existing img symlink

High Severity

The new allowlist accepts only public/images../images, but the repository also ships public/img../img. The preview guard still rejects that existing link, so the upload fails before Vercel can build.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 3ebed95. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant