New
Introducing React Bench, see how different models perform on React code

react-doctor/no-path-prefix-containment

Path containment check uses a string prefix

  • Category: Security
  • Severity: warn
  • Source: oxlint-plugin-react-doctor
  • Framework: global
  • Enabled when: always
  • Tags: test-noise
  • Default: Enabled

Validate the diagnostic

Confirm the reported code matches this rule before you edit it.

Confirm the reported code matches react-doctor/no-path-prefix-containment. Compare it with the Before example and verify the same API, framework, and execution context. Treat it as a false positive only when one of those conditions differs.

Compare the code

The corrected pattern shows a focused way to address the diagnostic.

Reported pattern

import path from "node:path";
const candidatePath = path.resolve(rootDirectory, requestedPath);
const isInside = candidatePath.startsWith(rootDirectory);

Corrected pattern

import path from "node:path";
const candidatePath = path.resolve(rootDirectory, requestedPath);
const relativePath = path.relative(rootDirectory, candidatePath);
const isInside =
  relativePath === "" ||
  (!relativePath.startsWith(`..${path.sep}`) &&
    relativePath !== ".." &&
    !path.isAbsolute(relativePath));

How to fix

Use the corrected pattern as a reference. Preserve behavior that the rule does not require you to change.

Copyable fix prompt

Copy this self-contained prompt into your coding agent after you confirm the diagnostic.

Fix every confirmed react-doctor/no-path-prefix-containment diagnostic in the current repository. Required change: - Use path.relative(root, candidate) and reject .. or absolute results instead of comparing path strings with the bare root prefix.
Reference transformation:Before:
import path from "node:path";
const candidatePath = path.resolve(rootDirectory, requestedPath);
const isInside = candidatePath.startsWith(rootDirectory);
After:
import path from "node:path";
const candidatePath = path.resolve(rootDirectory, requestedPath);
const relativePath = path.relative(rootDirectory, candidatePath);
const isInside =
  relativePath === "" ||
  (!relativePath.startsWith(`..${path.sep}`) &&
    relativePath !== ".." &&
    !path.isAbsolute(relativePath));
Constraints: - Confirm the reported code matches the Before pattern. - Make the smallest change that fixes the root cause. - Preserve behavior and interfaces unrelated to this diagnostic. - Reuse existing project components, utilities, and conventions. - Do not introduce render-phase side effects, render-phase state updates, or Hooks rule violations. - Keep validation and authorization on trusted boundaries. Do not replace them with client-only checks. - Adapt identifiers and framework details instead of copying blindly. - Do not disable the rule or suppress matching code. Verification: - Run focused tests for the changed behavior. - Run React Doctor and confirm this diagnostic no longer appears. - Report the files changed and any checks you could not run.

More Security rules from the rules reference:

  • react-doctor/no-secrets-in-client-code: Move secrets to server-only code. Public client environment variables are bundled into browser code and must not contain secrets
  • react-doctor/nosql-injection-risk: Building a NoSQL query from raw client input lets an attacker inject operator-shaped keys or `$where` code and read or alter data they should not.
  • react-doctor/package-metadata-secret: A secret or public-prefixed secret name in `package.json` leaks easily, because package metadata is routinely published to registries, logs, and browser bundles.
  • react-doctor/path-traversal-risk: Building a filesystem path from request input lets an attacker use `..` or absolute paths to read or write files outside the intended directory.
  • react-doctor/plugin-update-trust-risk: Downloading and running an update or plugin without verifying its integrity lets an attacker ship malicious code to your users.