|
tools: a non-admin may reach their own session directory
A non-admin was confined to user_data/<user_id>/ alone, which made four tools reject the directory the user's own uploads land in: share_file refused the file it was asked to send back, filesystem could not read it, and terminal/code_exec could not be pointed at it. In a prod session the agent worked around the refusal by copying the uploaded file into its sandbox with code_exec — the very bypass the injected security policy forbids — and the copy collided with a same-named file, so the user got a link to Project_1.mp3 instead of their own upload, plus an 8.6 MB duplicate. navi/tools/_internal/areas.py now names the two roots a user owns, and the four call sites share it. Relative paths still resolve into the sandbox, and each tool keeps its own way of refusing: terminal returns sandbox_violation, code_exec silently falls back to the sandbox root. The share_file refusal lists both roots instead of "outside user sandbox", so the agent retries in the right one instead of routing around it. The session directory belongs to the same user: its id arrives from the runtime context, never from tool arguments, and only the session's owner can open it. |
|---|
|
|
| docs/mechanics.md |
|---|
| manuals/code_exec.md |
|---|
| manuals/filesystem.md |
|---|
| manuals/share_file.md |
|---|
| manuals/terminal.md |
|---|
| navi/core/context_builder.py |
|---|
| navi/tools/_internal/areas.py 0 → 100644 |
|---|
| navi/tools/code_exec.py |
|---|
| navi/tools/filesystem.py |
|---|
| navi/tools/share_file.py |
|---|
| navi/tools/terminal.py |
|---|
| tests/unit/tools/test_areas.py 0 → 100644 |
|---|
| tests/unit/tools/test_code_exec.py |
|---|
| tests/unit/tools/test_filesystem.py |
|---|
| tests/unit/tools/test_share_file.py |
|---|
| tests/unit/tools/test_terminal.py |
|---|