fix (security): custom deny patterns denying default patterns

This commit is contained in:
Goksu Ceylan 2026-02-19 08:29:52 -05:00
parent 213274002a
commit e31685c8cf

View file

@ -80,6 +80,7 @@ func NewExecToolWithConfig(workingDir string, restrict bool, config *config.Conf
execConfig := config.Tools.Exec execConfig := config.Tools.Exec
enableDenyPatterns = execConfig.EnableDenyPatterns enableDenyPatterns = execConfig.EnableDenyPatterns
if enableDenyPatterns { if enableDenyPatterns {
denyPatterns = append(denyPatterns, defaultDenyPatterns...)
if len(execConfig.CustomDenyPatterns) > 0 { if len(execConfig.CustomDenyPatterns) > 0 {
fmt.Printf("Using custom deny patterns: %v\n", execConfig.CustomDenyPatterns) fmt.Printf("Using custom deny patterns: %v\n", execConfig.CustomDenyPatterns)
for _, pattern := range execConfig.CustomDenyPatterns { for _, pattern := range execConfig.CustomDenyPatterns {
@ -90,8 +91,6 @@ func NewExecToolWithConfig(workingDir string, restrict bool, config *config.Conf
} }
denyPatterns = append(denyPatterns, re) denyPatterns = append(denyPatterns, re)
} }
} else {
denyPatterns = append(denyPatterns, defaultDenyPatterns...)
} }
} else { } else {
// If deny patterns are disabled, we won't add any patterns, allowing all commands. // If deny patterns are disabled, we won't add any patterns, allowing all commands.