* Creates a regex pattern that matches safe invocations of a command. * * The regex ensures commands are invoked safely by blocking: * - Shell metacharacters that could lead to command injection or redirection * - Command substitution via backticks or $() * - Variable expansion that could conta
(command: string)
| 1420 | * @returns RegExp that matches safe invocations of the command |
| 1421 | */ |
| 1422 | function makeRegexForSafeCommand(command: string): RegExp { |
| 1423 | // Create regex pattern: /^command(?:\s|$)[^<>()$`|{}&;\n\r]*$/ |
| 1424 | return new RegExp(`^${command}(?:\\s|$)[^<>()$\`|{}&;\\n\\r]*$`) |
| 1425 | } |
| 1426 | |
| 1427 | // Simple commands that are safe for execution (converted to regex patterns using makeRegexForSafeCommand) |
| 1428 | // WARNING: If you are adding new commands here, be very careful to ensure |
nothing calls this directly
no outgoing calls
no test coverage detected