gnodet-bot commented on code in PR #387:
URL: https://github.com/apache/maven-filtering/pull/387#discussion_r4093439292
##########
src/main/java/org/apache/maven/shared/filtering/FilteringUtils.java:
##########
@@ -181,10 +181,10 @@ public static String getRelativeFilePath(final String
oldPath, final String newP
String toPath = new File(newPath).getPath();
// strip any leading slashes if its a windows path
- if (toPath.matches("^\\[a-zA-Z]:")) {
+ if (toPath.matches("^[/\\\\][a-zA-Z]:.*")) {
Review Comment:
⚠️ **Potential false positive on unusual Unix paths**
The pattern `^[/\\\\][a-zA-Z]:.*` will also match Unix paths like
`/a:/something` or `/b:/weird` — a single letter after a leading slash followed
by a colon. On Linux this is rare but not impossible (e.g. a path under a
directory literally named `a:`).
If such a path is passed, the leading `/` gets stripped and the leftover
`a:/something` then passes the `startsWith(":", 1)` drive-letter check at line
192, causing it to be treated as a Windows drive path on a Unix host.
The comment says _"strip any leading slashes **if it's a Windows path**"_,
so a guard like `toPath.matches("^[/\\\\][a-zA-Z]:[/\\\\].*")` (requiring a
separator after the colon) would avoid the false positive while covering the
same valid Windows cases (`/C:/foo`, `\\C:\\foo`). Worth considering, though in
practice such Unix paths would be unusual in a Maven resource-filtering context.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]