From 9728407539c37c4669b1a8b40aa52adef7e2de9c Mon Sep 17 00:00:00 2001 From: Bryan Van Deusen Date: Mon, 21 Sep 2026 11:05:37 -0400 Subject: [PATCH] docs: record why the misplaced-rows LIKE needs no escaping (4245) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `startswith` compiles to LIKE, where `_` and `%` are wildcards, and the call does not escape them. That is safe only because `slugify` reduces a slug to [a-z0-9-] — an invariant living in a different module, which is exactly the kind of thing that gets widened later without anyone connecting the two. Worth naming because `poch4n_art` is a real directory here: if slugs ever carried underscores, that prefix would start matching `poch4nXart` and the sweep would quietly mis-file one artist's rows. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01LVjrnpQjRgHdvq95rASoiR --- backend/app/services/library_layout.py | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/backend/app/services/library_layout.py b/backend/app/services/library_layout.py index 4e00dc3..f1c2eeb 100644 --- a/backend/app/services/library_layout.py +++ b/backend/app/services/library_layout.py @@ -54,6 +54,12 @@ def _misplaced_conditions(images_root: Path, artist_id: int, slug: str) -> list: `ara` would match every path under `arbuzbudesh/`, and the sweep would report one artist's whole library as correctly placed while quietly skipping another's. + + `startswith` compiles to LIKE, where `_` and `%` are wildcards, and this + does not escape them. That is safe ONLY because `utils.slug.slugify` + reduces a slug to `[a-z0-9-]` — neither character can reach the pattern. + Widen that charset and this needs `autoescape=True`, or `poch4n_art` + starts matching `poch4nXart` too. """ prefix = f"{canonical_dir(images_root, slug)}/" return [