react-doctor/no-path-prefix-containment
Path containment check uses a string prefix
- Category: Security
- Severity: warn
- Source:
oxlint-plugin-react-doctor - Framework: global
- Enabled when: always
- Tags: test-noise
- Default: Enabled
Validate the diagnostic
Confirm the reported code matches this rule before you edit it.
Confirm the reported code matches react-doctor/no-path-prefix-containment. Compare it with the Before example and verify the same API, framework, and execution context. Treat it as a false positive only when one of those conditions differs.
Compare the code
The corrected pattern shows a focused way to address the diagnostic.
Reported pattern
import path from "node:path";
const candidatePath = path.resolve(rootDirectory, requestedPath);
const isInside = candidatePath.startsWith(rootDirectory);Corrected pattern
import path from "node:path";
const candidatePath = path.resolve(rootDirectory, requestedPath);
const relativePath = path.relative(rootDirectory, candidatePath);
const isInside =
relativePath === "" ||
(!relativePath.startsWith(`..${path.sep}`) &&
relativePath !== ".." &&
!path.isAbsolute(relativePath));How to fix
Use the corrected pattern as a reference. Preserve behavior that the rule does not require you to change.
Copyable fix prompt
Copy this self-contained prompt into your coding agent after you confirm the diagnostic.
Fix every confirmed
Reference transformation:Before:react-doctor/no-path-prefix-containment diagnostic in the current repository.
Required change:
- Use path.relative(root, candidate) and reject .. or absolute results instead of comparing path strings with the bare root prefix.import path from "node:path";
const candidatePath = path.resolve(rootDirectory, requestedPath);
const isInside = candidatePath.startsWith(rootDirectory);import path from "node:path";
const candidatePath = path.resolve(rootDirectory, requestedPath);
const relativePath = path.relative(rootDirectory, candidatePath);
const isInside =
relativePath === "" ||
(!relativePath.startsWith(`..${path.sep}`) &&
relativePath !== ".." &&
!path.isAbsolute(relativePath));Constraints:
- Confirm the reported code matches the Before pattern.
- Make the smallest change that fixes the root cause.
- Preserve behavior and interfaces unrelated to this diagnostic.
- Reuse existing project components, utilities, and conventions.
- Do not introduce render-phase side effects, render-phase state updates, or Hooks rule violations.
- Keep validation and authorization on trusted boundaries. Do not replace them with client-only checks.
- Adapt identifiers and framework details instead of copying blindly.
- Do not disable the rule or suppress matching code.
Verification:
- Run focused tests for the changed behavior.
- Run React Doctor and confirm this diagnostic no longer appears.
- Report the files changed and any checks you could not run.
Related rules
More Security rules from the rules reference:
react-doctor/no-secrets-in-client-code: Move secrets to server-only code. Public client environment variables are bundled into browser code and must not contain secretsreact-doctor/nosql-injection-risk: Building a NoSQL query from raw client input lets an attacker inject operator-shaped keys or `$where` code and read or alter data they should not.react-doctor/package-metadata-secret: A secret or public-prefixed secret name in `package.json` leaks easily, because package metadata is routinely published to registries, logs, and browser bundles.react-doctor/path-traversal-risk: Building a filesystem path from request input lets an attacker use `..` or absolute paths to read or write files outside the intended directory.react-doctor/plugin-update-trust-risk: Downloading and running an update or plugin without verifying its integrity lets an attacker ship malicious code to your users.