Skip to content

fix(files): ignore empty segments in list extension filter - #392

Merged
petertzy merged 3 commits into
petertzy:mainfrom
harsh-thakkar7:fix/files-extension-filter-allows-extensionless
Oct 8, 2026
Merged

petertzy merged 3 commits into
petertzy:mainfrom
harsh-thakkar7:fix/files-extension-filter-allows-extensionless

Conversation

@harsh-thakkar7

Copy link
Copy Markdown
Contributor

What

A comma-separated extension filter like md, (stray trailing comma) put an empty string into the extension allowlist, so extensionless files leaked into the listing even though only .md files were requested.

Observed:

  • GET /api/files/list?extensions=md → ["a.md"]
  • GET /api/files/list?extensions=md, → ["a.md", "noext"] (wrong)

Fix

Skip empty segments when building the allowlist, so md,, md, and ,md all behave exactly like md.

Tests

  • tests/test_files_endpoints.py: new endpoint tests asserting the trailing-comma forms never return the extensionless file.
  • Full backend suite passes (471 tests). Ruff clean.

harsh-thakkar7 and others added 3 commits October 8, 2026 16:26
A filter like 'md,' put an empty string in the extension allowlist, so
extensionless files leaked into the listing even though the caller only
asked for .md files. Skip empty segments so 'md,' behaves like 'md'.
@petertzy

petertzy commented Oct 8, 2026

Copy link
Copy Markdown
Owner

Approved — this is a necessary correctness fix. Empty comma-separated extension segments no longer cause extensionless files to leak into a filtered listing.
I also hardened normalization so segments such as . and .., which become empty after optional leading dots are removed, are discarded as well. Endpoint coverage includes trailing commas, whitespace, leading commas, and normalized-empty segments. Backend tests (487 passed), frontend tests (94/94), Ruff, ESLint, and TypeScript checks all pass.

@petertzy
petertzy merged commit 2aebdc2 into petertzy:main Oct 8, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants