Skip to content

Conversation

@padznich
Copy link

@padznich padznich commented Feb 12, 2026

Strip any directory traversal

PR checklist

  • Read the contribution guidelines.
  • Pull Request title clearly describes the work in the pull request and Pull Request description provides details about how to validate the work. Missing information here may result in delayed response from the community.
  • Run the following to build the project and update samples:
    ./mvnw clean package || exit
    ./bin/generate-samples.sh ./bin/configs/*.yaml || exit
    ./bin/utils/export_docs_generators.sh || exit
    
    (For Windows users, please run the script in WSL)
    Commit all changed files.
    This is important, as CI jobs will verify all generator outputs of your HEAD commit as it would merge with master.
    These must match the expectations made by your contribution.
    You may regenerate an individual generator by passing the relevant config(s) as an argument to the script, for example ./bin/generate-samples.sh bin/configs/java*.
    IMPORTANT: Do NOT purge/delete any folders/files (e.g. tests) when regenerating the samples as manually written tests may be removed.

Summary by cubic

Updated Python SDK to safely save downloaded files by stripping path components from Content-Disposition filenames. Regenerated generator docs and samples to reflect the change.

  • Bug Fixes
    • Python: use os.path.basename on the Content-Disposition filename so files are written only to the target directory.

Written for commit 215cb98. Summary will update on new commits.

Copy link
Contributor

@cubic-dev-ai cubic-dev-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

2 issues found across 74 files

Prompt for AI agents (all issues)

Check if these issues are valid — if so, understand the root cause of each and fix them.


<file name="docs/generators/swift5.md">

<violation number="1" location="docs/generators/swift5.md:10">
P2: The docs now claim the swift5 generator is STABLE, but the generator metadata in code still marks it DEPRECATED, causing a mismatch between docs and actual generator status.</violation>
</file>

<file name="docs/generators/kotlin-server.md">

<violation number="1" location="docs/generators/kotlin-server.md:265">
P2: Documentation now claims Polymorphism/allOf/oneOf are unsupported, but KotlinServerCodegen explicitly includes these schema support features, creating a mismatch that can mislead users.</violation>
</file>

Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.

@wing328
Copy link
Member

wing328 commented Feb 12, 2026

looks like your PR is not based on the latest master

can you please file a new one based on the latest master or merge the latest master into your branch (and update both samples and docs)?

cc @cbornet (2017/09) @tomplus (2018/10) @krjakbrjak (2023/02) @fa0311 (2023/10) @multani (2023/10)

Strip any directory traversal
@padznich padznich force-pushed the python-sdk-dir-traversal-fix branch from 67cf2a8 to 215cb98 Compare February 12, 2026 14:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants