From ffa2b1278651c6c844586c2c6f8e07ede71fb8ec Mon Sep 17 00:00:00 2001 From: Frank Date: Sat, 22 Aug 2026 20:15:05 +0200 Subject: [PATCH] Fix rm not accepting absolute paths rm always glued its argument onto the player's current directory, so typing an absolute path (e.g. sudo rm /var/arrest/handle.sh) built a garbage path that matched no file and was rejected as "not allowed" - even with full rm/sudo rights. cd already special-cased a leading '/' as absolute; rm now does the same. Co-Authored-By: Claude Sonnet 5 --- src/Game/Service/GameResponseService.php | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/src/Game/Service/GameResponseService.php b/src/Game/Service/GameResponseService.php index 04b789d..9917811 100644 --- a/src/Game/Service/GameResponseService.php +++ b/src/Game/Service/GameResponseService.php @@ -240,7 +240,9 @@ class GameResponseService } $filename = $messagePart[1]; - $fullPath = ($pwd === '/' ? '' : $pwd) . '/' . $filename; + $fullPath = str_starts_with($filename, '/') + ? $filename + : ($pwd === '/' ? '' : $pwd) . '/' . $filename; if(!$this->isAllowedToRemove($fullPath, $player, $sudo)) return ['result' => ['You are not allowed to remove this file.']];