paperclipai/paperclip · error
Invalid object key for company
Error message
Invalid object key for company ${companyId}. What it means
Multi-tenancy isolation guard on storage object keys: an object key that does not start with the owning company's id prefix, or contains '..' traversal, is rejected so one company's worktree storage client can never read or write another company's objects.
Solutions
- Use a valid object key for the company; check the key format and company ID.
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at cli/src/commands/worktree.ts:292 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of paperclipai/paperclip@01ad858492 (2026-08-18).
Data as JSON: /api/errors/7fa5da6a74e00c02.
Report an issue: GitHub.
Appendix: source
Thrown at cli/src/commands/worktree.ts:325
return value.startsWith(WORKTREE_NAME_PREFIX) ? value : `${WORKTREE_NAME_PREFIX}${value}`;
}
function resolveWorktreeHome(explicit?: string): string {
return explicit ?? process.env.PAPERCLIP_WORKTREES_DIR ?? DEFAULT_WORKTREE_HOME;
}
function resolveWorktreeStartPoint(explicit?: string): string | undefined {
return explicit ?? nonEmpty(process.env.PAPERCLIP_WORKTREE_START_POINT) ?? undefined;
}
type ConfiguredStorage = {
getObject(companyId: string, objectKey: string): Promise<Buffer>;
putObject(companyId: string, objectKey: string, body: Buffer, contentType: string): Promise<void>;
};
function assertStorageCompanyPrefix(companyId: string, objectKey: string): void {
if (!objectKey.startsWith(`${companyId}/`) || objectKey.includes("..")) {
throw new Error(`Invalid object key for company ${companyId}.`);
}
}
function normalizeStorageObjectKey(objectKey: string): string {
const normalized = objectKey.replace(/\\/g, "/").trim();
if (!normalized || normalized.startsWith("/")) {
throw new Error("Invalid object key.");
}
const parts = normalized.split("/").filter((part) => part.length > 0);
if (parts.length === 0 || parts.some((part) => part === "." || part === "..")) {
throw new Error("Invalid object key.");
}
return parts.join("/");
}
function resolveLocalStoragePath(baseDir: string, objectKey: string): string {
const resolved = path.resolve(baseDir, normalizeStorageObjectKey(objectKey));
const root = path.resolve(baseDir);View on GitHub (pinned to 01ad858492)