Archive extraction path not validated
Review this Go archive extractor.
What a strong answer looks like
Separate real bugs from style. Rank issues by severity, point at the root cause rather than the symptom, and suggest a concrete fix, specific and kind.
0:00 of about 30 min
Mark a line and say what kind of problem it is.0 findings
1func extract(zr *zip.Reader, dest string) error {
2 for _, f := range zr.File {
3 target := filepath.Join(dest, f.Name)
4 os.MkdirAll(filepath.Dir(target), 0755)
5 out, err := os.Create(target)
6 if err != nil { return err }
7 rc, _ := f.Open()
8 io.Copy(out, rc)
9 out.Close(); rc.Close()
10 }
11 return nil
12}
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.
Run or narrate your approach, then ask the coach.