Workflow improvement
Configure an explicit trusted root for exported/uploaded files.
Proposed implementation
Preserve CWD confinement by default. Add a user-controlled environment variable GOOGLE_WORKSPACE_CLI_FILE_ROOT for --output/--upload file-path validation, consistent with AGENTS.md distinction that environment is trusted. When set, canonicalize and require an existing directory. Permit canonical file paths within that root (including absolute paths) while rejecting control characters, parent traversal, symlink escapes and invalid roots. Relative CLI paths still resolve relative to process CWD; document clearly that root changes the allowed boundary, not relative path interpretation. Restrict change to shared file-path validator and these documented flags; do not silently expand all directory helpers. No unrestricted allow-all flag; no weakening default. Errors should name boundary and explain how operator can choose a root through environment. Thread explicit policy to pure validation helper for tests where possible; tests manipulating environment serialized/restored. Default output behavior and file creation should remain unchanged.
Acceptance criteria and tests
Unconfigured behavior unchanged; configured /tmp-like root accepts absolute child output and existing upload; rejects sibling, ../, symlink outside, nonexistent/non-directory root; existing symlink inside accepted if policy already allows; relative paths remain CWD-relative; nested new file parent checks; no environment leakage across tests; CLI integration with synthetic discovery/dry-run verifies propagated canonical output.
Upstream coordination
Related: googleworkspace#743.
This fork issue tracks one independent contribution from our document-workflow improvement effort. Existing upstream issues remain the canonical reports; the resulting PR will target googleworkspace/cli and reference them.
Delivery
- Separate branch:
feat/scoped-file-roots.
- Tests first, independent code review, required checks and changeset.
- Synthetic fixtures only; no personal documents or credentials in public artifacts.
Implementation PR: googleworkspace#935
Workflow improvement
Configure an explicit trusted root for exported/uploaded files.
Proposed implementation
Preserve CWD confinement by default. Add a user-controlled environment variable GOOGLE_WORKSPACE_CLI_FILE_ROOT for --output/--upload file-path validation, consistent with AGENTS.md distinction that environment is trusted. When set, canonicalize and require an existing directory. Permit canonical file paths within that root (including absolute paths) while rejecting control characters, parent traversal, symlink escapes and invalid roots. Relative CLI paths still resolve relative to process CWD; document clearly that root changes the allowed boundary, not relative path interpretation. Restrict change to shared file-path validator and these documented flags; do not silently expand all directory helpers. No unrestricted allow-all flag; no weakening default. Errors should name boundary and explain how operator can choose a root through environment. Thread explicit policy to pure validation helper for tests where possible; tests manipulating environment serialized/restored. Default output behavior and file creation should remain unchanged.
Acceptance criteria and tests
Unconfigured behavior unchanged; configured /tmp-like root accepts absolute child output and existing upload; rejects sibling, ../, symlink outside, nonexistent/non-directory root; existing symlink inside accepted if policy already allows; relative paths remain CWD-relative; nested new file parent checks; no environment leakage across tests; CLI integration with synthetic discovery/dry-run verifies propagated canonical output.
Upstream coordination
Related: googleworkspace#743.
This fork issue tracks one independent contribution from our document-workflow improvement effort. Existing upstream issues remain the canonical reports; the resulting PR will target googleworkspace/cli and reference them.
Delivery
feat/scoped-file-roots.Implementation PR: googleworkspace#935