{"record":{"id":"7fa5da6a74e00c02","repo":"paperclipai/paperclip","slug":"invalid-object-key-for-company-companyid","errorCode":null,"errorMessage":"Invalid object key for company ${companyId}.","messagePattern":"Invalid object key for company (.+?)\\.","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"cli/src/commands/worktree.ts","lineNumber":325,"sourceCode":"  return value.startsWith(WORKTREE_NAME_PREFIX) ? value : `${WORKTREE_NAME_PREFIX}${value}`;\n}\n\nfunction resolveWorktreeHome(explicit?: string): string {\n  return explicit ?? process.env.PAPERCLIP_WORKTREES_DIR ?? DEFAULT_WORKTREE_HOME;\n}\n\nfunction resolveWorktreeStartPoint(explicit?: string): string | undefined {\n  return explicit ?? nonEmpty(process.env.PAPERCLIP_WORKTREE_START_POINT) ?? undefined;\n}\n\ntype ConfiguredStorage = {\n  getObject(companyId: string, objectKey: string): Promise<Buffer>;\n  putObject(companyId: string, objectKey: string, body: Buffer, contentType: string): Promise<void>;\n};\n\nfunction assertStorageCompanyPrefix(companyId: string, objectKey: string): void {\n  if (!objectKey.startsWith(`${companyId}/`) || objectKey.includes(\"..\")) {\n    throw new Error(`Invalid object key for company ${companyId}.`);\n  }\n}\n\nfunction normalizeStorageObjectKey(objectKey: string): string {\n  const normalized = objectKey.replace(/\\\\/g, \"/\").trim();\n  if (!normalized || normalized.startsWith(\"/\")) {\n    throw new Error(\"Invalid object key.\");\n  }\n  const parts = normalized.split(\"/\").filter((part) => part.length > 0);\n  if (parts.length === 0 || parts.some((part) => part === \".\" || part === \"..\")) {\n    throw new Error(\"Invalid object key.\");\n  }\n  return parts.join(\"/\");\n}\n\nfunction resolveLocalStoragePath(baseDir: string, objectKey: string): string {\n  const resolved = path.resolve(baseDir, normalizeStorageObjectKey(objectKey));\n  const root = path.resolve(baseDir);","sourceCodeStart":307,"sourceCodeEnd":343,"githubUrl":"https://github.com/paperclipai/paperclip/blob/01ad8584922b5d85292b1723cae71fa0d9b07a19/cli/src/commands/worktree.ts#L307-L343","documentation":"Multi-tenancy isolation guard on storage object keys: an object key that does not start with the owning company's id prefix, or contains '..' traversal, is rejected so one company's worktree storage client can never read or write another company's objects.","triggerScenarios":"Thrown at cli/src/commands/worktree.ts:292 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Use a valid object key for the company; check the key format and company ID."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"01ad8584922b5d85292b1723cae71fa0d9b07a19","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}