{"record":{"id":"2bc006ece8f1da64","repo":"paperclipai/paperclip","slug":"invalid-install-payload-identifier-identifier","errorCode":null,"errorMessage":"Invalid install payload identifier '${identifier}'.","messagePattern":"Invalid install payload identifier '(.+?)'\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"cli/src/install-store.ts","lineNumber":210,"sourceCode":"    return await callback();\n  } finally {\n    try {\n      if (fs.readFileSync(paths.lockPath, \"utf8\").trim() === token) {\n        fs.rmSync(paths.lockPath, { force: true });\n      }\n    } catch (error) {\n      if ((error as NodeJS.ErrnoException).code !== \"ENOENT\") throw error;\n    }\n  }\n}\n\nexport function payloadPathFor(\n  paths: InstallStorePaths,\n  source: InstallSource,\n  identifier: string,\n): string {\n  if (!/^[A-Za-z0-9._-]+$/.test(identifier)) {\n    throw new Error(`Invalid install payload identifier '${identifier}'.`);\n  }\n  return path.join(paths.installsRoot, source, identifier);\n}\n\nexport function readInstallManifest(paths = resolveInstallStorePaths()): InstallManifest | null {\n  try {\n    const value = JSON.parse(fs.readFileSync(paths.manifestPath, \"utf8\")) as InstallManifest;\n    if (\n      value.schemaVersion !== INSTALL_MANIFEST_VERSION ||\n      (value.source !== \"npm\" && value.source !== \"git\") ||\n      !Array.isArray(value.previous) ||\n      typeof value.payloadPath !== \"string\"\n    ) {\n      throw new Error(\"unsupported manifest shape\");\n    }\n    return value;\n  } catch (error) {\n    if ((error as NodeJS.ErrnoException).code === \"ENOENT\") return null;","sourceCodeStart":192,"sourceCodeEnd":228,"githubUrl":"https://github.com/paperclipai/paperclip/blob/01ad8584922b5d85292b1723cae71fa0d9b07a19/cli/src/install-store.ts#L192-L228","documentation":"payloadPathFor validates the payload identifier against a safe filename charset; the identifier contains characters outside [A-Za-z0-9._-] and would escape the payload directory scheme.","triggerScenarios":"Thrown at cli/src/install-store.ts:210 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Use a valid install payload identifier (a simple name without path separators or traversal)."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"01ad8584922b5d85292b1723cae71fa0d9b07a19","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}