Ensure each tenant's notes are stored in an isolated filesystem directory with proper sandboxing to prevent cross-tenant data access.
Design
Each user gets a dedicated directory: data/{user_id}/
All file operations scoped to the user's directory
Path traversal prevention (canonicalize and validate all paths)
Symlink following disabled within user directories
Implementation Tasks
Create user directory on first login/registration
Modify note CRUD operations to scope to user directory
Add path validation to prevent directory traversal (../, symlinks)
Add filesystem permission enforcement
Write tests for path traversal attack vectors
Security Considerations
Must prevent ../ path traversal attacks
Must prevent symlink-based escapes
Must validate all file paths against user's root directory
Race condition protection on file operations
Acceptance Criteria
Each user can only access their own notes directory
Path traversal attempts return 403/404
Symlink-based escapes are blocked
Unit tests cover all known traversal vectors
## Summary
Ensure each tenant's notes are stored in an isolated filesystem directory with proper sandboxing to prevent cross-tenant data access.
## Design
- Each user gets a dedicated directory: data/{user_id}/
- All file operations scoped to the user's directory
- Path traversal prevention (canonicalize and validate all paths)
- Symlink following disabled within user directories
## Implementation Tasks
- [x] Create user directory on first login/registration
- [x] Modify note CRUD operations to scope to user directory
- [x] Add path validation to prevent directory traversal (../, symlinks)
- [x] Add filesystem permission enforcement
- [x] Write tests for path traversal attack vectors
## Security Considerations
- Must prevent ../ path traversal attacks
- Must prevent symlink-based escapes
- Must validate all file paths against user's root directory
- Race condition protection on file operations
## Acceptance Criteria
- [x] Each user can only access their own notes directory
- [x] Path traversal attempts return 403/404
- [x] Symlink-based escapes are blocked
- [x] Unit tests cover all known traversal vectors
libretech
changed title from Implement per-user note directory isolation to Implement per-user note directory isolation with filesystem sandboxing2026-03-01 20:31:26 +01:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Ensure each tenant's notes are stored in an isolated filesystem directory with proper sandboxing to prevent cross-tenant data access.
Design
Implementation Tasks
Security Considerations
Acceptance Criteria
Per-user note directory isolationto Implement per-user note directory isolationImplement per-user note directory isolationto Implement per-user note directory isolation with filesystem sandboxing