{"record":{"id":"792e4bcf6b1a4a81","repo":"Mintplex-Labs/anything-llm","slug":"invalid-path","errorCode":null,"errorMessage":"Invalid path.","messagePattern":"Invalid path\\.","errorType":"exception","errorClass":"Error","httpStatus":500,"severity":"error","filePath":"server/utils/files/index.js","lineNumber":394,"sourceCode":" * @returns {boolean} True if `inner` is strictly inside `outer`, false otherwise.\n */\nfunction isWithin(outer, inner) {\n  const resolvedOuter = path.resolve(outer);\n  const resolvedInner = path.resolve(inner);\n  const rel = path.relative(resolvedOuter, resolvedInner);\n\n  if (rel === \"\") return false;\n  return (\n    !rel.startsWith(`..${path.sep}`) && rel !== \"..\" && !path.isAbsolute(rel)\n  );\n}\n\nfunction normalizePath(filepath = \"\") {\n  const result = path\n    .normalize(filepath.trim())\n    .replace(/^(\\.\\.(\\/|\\\\|$))+/, \"\")\n    .trim();\n  if ([\"..\", \".\", \"/\"].includes(result)) throw new Error(\"Invalid path.\");\n  return result;\n}\n\n/**\n * Strips characters that are illegal in Windows filenames, including Unicode\n * quotation marks (U+201C, U+201D, etc.) that can get corrupted into ASCII\n * double-quotes during charset conversion in the upload pipeline.\n * @param {string} fileName - The filename to sanitize.\n * @returns {string} - The sanitized filename.\n */\nfunction sanitizeFileName(fileName) {\n  if (!fileName) return fileName;\n  return fileName.replace(\n    /[<>:\"/\\\\|?*\\u201C\\u201D\\u201E\\u201F\\u2018\\u2019\\u201A\\u201B]/g,\n    \"\"\n  );\n}\n","sourceCodeStart":376,"sourceCodeEnd":412,"githubUrl":"https://github.com/Mintplex-Labs/anything-llm/blob/f92433b4ea0598492a1e6645ea22addbb4dd1287/server/utils/files/index.js#L376-L412","documentation":"Sanitization guard in normalizePath: after trimming and stripping traversal prefixes, the path resolves to a pure relative anchor ('..', '.', or '/'), meaning the supplied filepath denotes no concrete file location and would be unsafe to join, so it is rejected.","triggerScenarios":"A file operation received an invalid or unsafe path.","commonSituations":"This error is raised at runtime in server/utils/files/index.js. It occurs when the required configuration for this provider is missing or invalid (unset environment variables, empty API key or base path), when the external service is unreachable or returns an unexpected response, or when invalid input reaches the call site. To prevent it, validate the relevant provider settings and environment variables at startup and confirm the service is reachable before this code path executes.","solutions":["Provide a valid, normalized path inside the allowed documents directory.","Remove path traversal segments from the supplied path."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"f92433b4ea0598492a1e6645ea22addbb4dd1287","analyzedAt":"2026-08-18T10:02:21.017Z","contentChangedAt":"2026-08-18T10:02:21.017Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}