paperclipai/paperclip · error
Invalid object key path.
Error message
Invalid object key path.
What it means
Path-escape guard for local storage: resolving the normalized object key against the storage base directory produced a path outside that directory, so the key would address files outside the storage root and is rejected.
Solutions
- Fix the object key path; remove traversal segments and invalid characters.
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at cli/src/commands/worktree.ts:312 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of paperclipai/paperclip@01ad858492 (2026-08-18).
Data as JSON: /api/errors/b41b517275014e06.
Report an issue: GitHub.
Appendix: source
Thrown at cli/src/commands/worktree.ts:345
}
function normalizeStorageObjectKey(objectKey: string): string {
const normalized = objectKey.replace(/\\/g, "/").trim();
if (!normalized || normalized.startsWith("/")) {
throw new Error("Invalid object key.");
}
const parts = normalized.split("/").filter((part) => part.length > 0);
if (parts.length === 0 || parts.some((part) => part === "." || part === "..")) {
throw new Error("Invalid object key.");
}
return parts.join("/");
}
function resolveLocalStoragePath(baseDir: string, objectKey: string): string {
const resolved = path.resolve(baseDir, normalizeStorageObjectKey(objectKey));
const root = path.resolve(baseDir);
if (resolved !== root && !resolved.startsWith(`${root}${path.sep}`)) {
throw new Error("Invalid object key path.");
}
return resolved;
}
async function s3BodyToBuffer(body: unknown): Promise<Buffer> {
if (!body) {
throw new Error("Object not found.");
}
if (Buffer.isBuffer(body)) {
return body;
}
if (body instanceof Readable) {
return await streamToBuffer(body);
}
const candidate = body as {
transformToWebStream?: () => ReadableStream<Uint8Array>;
arrayBuffer?: () => Promise<ArrayBuffer>;View on GitHub (pinned to 01ad858492)