{"record":{"id":"a1fe279cb4e4144a","repo":"thedotmack/claude-mem","slug":"refusing-inject-path-for-non-uuid-agent-id-agentid","errorCode":null,"errorMessage":"Refusing inject path for non-UUID agent id: ${agentId}","messagePattern":"Refusing inject path for non-UUID agent id: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/services/integrations/grok-bot-index-format.ts","lineNumber":163,"sourceCode":"\nexport function renderIndexFile(factLines: string[]): string {\n  return `${FILE_HEADER}${factLines.join('\\n')}\\n`;\n}\n\nexport function factBlock(contents: string): string {\n  return String(contents ?? '')\n    .split('\\n')\n    .filter(line => line.startsWith('- ('))\n    .join('\\n');\n}\n\nexport function shouldRewriteInject(existingContents: string, nextContents: string): boolean {\n  return factBlock(existingContents) !== factBlock(nextContents);\n}\n\nexport function injectLogPath(agentDataRoot: string, agentId: string): string {\n  if (!AGENT_ID_RE.test(agentId)) {\n    throw new Error(`Refusing inject path for non-UUID agent id: ${agentId}`);\n  }\n  return path.join(agentDataRoot, 'agents', agentId, 'memory', 'log', INJECT_LOG_BASENAME);\n}\n\nexport function assertSafeInjectPath(agentDataRoot: string, agentId: string, filePath: string): void {\n  const expectedDir = path.resolve(path.join(agentDataRoot, 'agents', agentId, 'memory', 'log'));\n  const resolved = path.resolve(filePath);\n  if (path.basename(resolved).toLowerCase() === 'profile.md') {\n    throw new Error('Refusing write to profile.md');\n  }\n  if (path.dirname(resolved) !== expectedDir) {\n    throw new Error('Refusing inject write outside agent memory/log');\n  }\n  if (path.basename(resolved) !== INJECT_LOG_BASENAME) {\n    throw new Error(`Refusing inject write to a file this writer does not own: ${path.basename(resolved)}`);\n  }\n}\n","sourceCodeStart":145,"sourceCodeEnd":181,"githubUrl":"https://github.com/thedotmack/claude-mem/blob/d8bc9755e74915e5c3b999181e10a67c889bce2a/src/services/integrations/grok-bot-index-format.ts#L145-L181","documentation":"injectLogPath builds the filesystem path for an agent's inject log under agentDataRoot/agents/<agentId>/memory/log. It throws when agentId does not match AGENT_ID_RE (UUID format), preventing path injection or directory traversal through a crafted agent id.","triggerScenarios":"injectLogPath (via callers like filePath) is called with an agentId that is not a UUID — empty string, a project name, a path like '../x', or an id from an older data format.","commonSituations":"Legacy records store non-UUID agent ids; a caller passes a slug or display name instead of the UUID; corrupted DB rows or user-supplied ids flow into the memory writer.","solutions":["Pass the agent's UUID as agentId (e.g. '550e8400-e29b-41d4-a716-446655440000'), matching AGENT_ID_RE.","Look up the correct UUID from the agent registry if you only have a name or slug.","Add a guard before calling: test the id against a UUID regex and reject or regenerate invalid ids."],"exampleFix":"// before\nconst p = injectLogPath(root, agent.name); // 'my-grok-bot'\n// after\nconst p = injectLogPath(root, agent.uuid); // '3f2504e0-4f89-11d3-9a0c-0305e82c3301'","handlingStrategy":"validation","validationCode":"const UUID_RE = /^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$/i;\nif (!UUID_RE.test(agentId)) throw new Error(`bad agent id: ${agentId}`);\nconst p = injectLogPath(root, agentId);","typeGuard":"function isUuid(v: string): boolean {\n  return /^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$/i.test(v);\n}","tryCatchPattern":"let p: string;\ntry {\n  p = injectLogPath(root, agentId);\n} catch (err) {\n  logger.error('Non-UUID agent id, skipping inject log write', { agentId }, err);\n  return;\n}","preventionTips":["Always source agentId from the agent registry, never from user input or display names.","Validate ids at ingestion time so bad ids never reach storage.","Normalize ids to lowercase before use."],"tags":["validation","path","security"],"backgroundTag":"invalid-identifier-format","analyzedSha":"d8bc9755e74915e5c3b999181e10a67c889bce2a","analyzedAt":"2026-09-17T16:40:26.182Z","contentChangedAt":"2026-09-17T16:40:26.182Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}