# `react-doctor/no-path-prefix-containment`

Path containment check uses a string prefix

- **Category:** Security
- **Severity:** warn
- **Source:** oxlint-plugin-react-doctor
- **Framework:** global
- **Enabled when:** always

## Validate the diagnostic

Confirm the reported code matches this rule before you edit it.

Confirm the reported code matches `react-doctor/no-path-prefix-containment`. Compare it with the Before example and verify the same API, framework, and execution context. Treat it as a false positive only when one of those conditions differs.

## Compare the code

The corrected pattern shows a focused way to address the diagnostic.

### Reported pattern

```ts
import path from "node:path";
const candidatePath = path.resolve(rootDirectory, requestedPath);
const isInside = candidatePath.startsWith(rootDirectory);
```

### Corrected pattern

```ts
import path from "node:path";
const candidatePath = path.resolve(rootDirectory, requestedPath);
const relativePath = path.relative(rootDirectory, candidatePath);
const isInside =
  relativePath === "" ||
  (!relativePath.startsWith(`..${path.sep}`) &&
    relativePath !== ".." &&
    !path.isAbsolute(relativePath));
```

## How to fix

Use the corrected pattern as a reference. Preserve behavior that the rule does not require you to change.

### Copyable fix prompt

Copy this self-contained prompt into your coding agent after you confirm the diagnostic.

````text
Fix every confirmed `react-doctor/no-path-prefix-containment` diagnostic in the current repository.

Required change:
- Use `path.relative(root, candidate)` and reject `..` or absolute results instead of comparing path strings with the bare root prefix.

Reference transformation:

Before:
```ts
import path from "node:path";
const candidatePath = path.resolve(rootDirectory, requestedPath);
const isInside = candidatePath.startsWith(rootDirectory);
```

After:
```ts
import path from "node:path";
const candidatePath = path.resolve(rootDirectory, requestedPath);
const relativePath = path.relative(rootDirectory, candidatePath);
const isInside =
  relativePath === "" ||
  (!relativePath.startsWith(`..${path.sep}`) &&
    relativePath !== ".." &&
    !path.isAbsolute(relativePath));
```

Constraints:
- Confirm the reported code matches the Before pattern.
- Make the smallest change that fixes the root cause.
- Preserve behavior and interfaces unrelated to this diagnostic.
- Reuse existing project components, utilities, and conventions.
- Do not introduce render-phase side effects, render-phase state updates, or Hooks rule violations.
- Keep validation and authorization on trusted boundaries. Do not replace them with client-only checks.
- Adapt identifiers and framework details instead of copying blindly.
- Do not disable the rule or suppress matching code.

Verification:
- Run focused tests for the changed behavior.
- Run React Doctor and confirm this diagnostic no longer appears.
- Report the files changed and any checks you could not run.
````
