Code RoomArchive extraction path not validated
HardPrep Room Coding #1883

Archive extraction path not validated

Code reviewCode quality & reviewSenior–Staff~30 min

Review this Go archive extractor.

What a strong answer looks like

Separate real bugs from style. Rank issues by severity, point at the root cause rather than the symptom, and suggest a concrete fix, specific and kind.

0:00 of about 30 min
Mark a line and say what kind of problem it is.0 findings
1func extract(zr *zip.Reader, dest string) error {
2 for _, f := range zr.File {
3 target := filepath.Join(dest, f.Name)
4 os.MkdirAll(filepath.Dir(target), 0755)
5 out, err := os.Create(target)
6 if err != nil { return err }
7 rc, _ := f.Open()
8 io.Copy(out, rc)
9 out.Close(); rc.Close()
10 }
11 return nil
12}
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.