Reject manifest metadata as storage paths
GeoIntel release gates / Compile, test, contracts and builds (push) Canceled after 0s
GeoIntel release gates / Python and npm vulnerability policy (push) Canceled after 0s
GeoIntel release gates / GIS image, SBOM and container scan (push) Canceled after 0s

This commit is contained in:
Codex
2026-07-18 07:28:50 +02:00
parent 556eeb21af
commit dbdc594f94
2 changed files with 24 additions and 3 deletions
+22 -3
View File
@@ -143,18 +143,37 @@ def _iter_strings(value: Any) -> Iterable[str]:
yield from _iter_strings(nested)
def _manifest_key_is_path(key: str) -> bool:
exact = {
"path",
"paths",
"file",
"files",
"filename",
"filenames",
"artifact",
"artifacts",
"manifest",
"manifests",
"storage_path",
"source_tile_path",
"mask_path",
"output_path",
}
return key in exact or key.endswith(("_path", "_paths", "_file", "_files", "_filename", "_filenames"))
def _iter_manifest_path_values(value: Any, parent_key: str = "") -> Iterable[str]:
path_tokens = ("path", "file", "artifact", "manifest", "output")
if isinstance(value, dict):
for key, nested in value.items():
normalized_key = str(key).strip().lower()
if isinstance(nested, str) and any(token in normalized_key for token in path_tokens):
if isinstance(nested, str) and _manifest_key_is_path(normalized_key):
yield nested
else:
yield from _iter_manifest_path_values(nested, normalized_key)
elif isinstance(value, (list, tuple)):
for nested in value:
if isinstance(nested, str) and any(token in parent_key for token in path_tokens):
if isinstance(nested, str) and _manifest_key_is_path(parent_key):
yield nested
else:
yield from _iter_manifest_path_values(nested, parent_key)