paperclipai/paperclip · error
Invalid object key.
Error message
Invalid object key.
What it means
Canonicalization guard for storage object keys: after normalizing backslashes and trimming, the key is empty, rooted (leading '/'), or contains '.'/'..' path segments, so it cannot map safely into a flat storage namespace.
Solutions
- Use a valid object key format.
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at cli/src/commands/worktree.ts:299 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of paperclipai/paperclip@01ad858492 (2026-08-18).
Data as JSON: /api/errors/67db43c17da96088.
Report an issue: GitHub.
Appendix: source
Thrown at cli/src/commands/worktree.ts:332
function resolveWorktreeStartPoint(explicit?: string): string | undefined {
return explicit ?? nonEmpty(process.env.PAPERCLIP_WORKTREE_START_POINT) ?? undefined;
}
type ConfiguredStorage = {
getObject(companyId: string, objectKey: string): Promise<Buffer>;
putObject(companyId: string, objectKey: string, body: Buffer, contentType: string): Promise<void>;
};
function assertStorageCompanyPrefix(companyId: string, objectKey: string): void {
if (!objectKey.startsWith(`${companyId}/`) || objectKey.includes("..")) {
throw new Error(`Invalid object key for company ${companyId}.`);
}
}
function normalizeStorageObjectKey(objectKey: string): string {
const normalized = objectKey.replace(/\\/g, "/").trim();
if (!normalized || normalized.startsWith("/")) {
throw new Error("Invalid object key.");
}
const parts = normalized.split("/").filter((part) => part.length > 0);
if (parts.length === 0 || parts.some((part) => part === "." || part === "..")) {
throw new Error("Invalid object key.");
}
return parts.join("/");
}
function resolveLocalStoragePath(baseDir: string, objectKey: string): string {
const resolved = path.resolve(baseDir, normalizeStorageObjectKey(objectKey));
const root = path.resolve(baseDir);
if (resolved !== root && !resolved.startsWith(`${root}${path.sep}`)) {
throw new Error("Invalid object key path.");
}
return resolved;
}
async function s3BodyToBuffer(body: unknown): Promise<Buffer> {View on GitHub (pinned to 01ad858492)