noCV
CDOWN-103 · Describe downloads

Validate course manifest paths before creating files

Practice briefBugIntermediate

A malformed manifest filename can escape its course directory. Restrict all destinations to a scoped cache root.

Focused work estimate
2h + prerequisites
Priority in the scenario
High
Engineering practice
Filesystem · Input security

Estimated field mix

  • Security60%
  • Storage systems20%
  • Mobile20%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

Fictional learning app Birch offers synthetic text and small local media fixtures through a loopback adapter. No copyrighted course assets or network accounts are needed.

Setup prerequisites

  • Create small local byte fixtures and a range-response stub.
  • Simulate low storage, interruptions and stale manifests.

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Traversal is rejected
  • Absolute paths are rejected
  • Valid nested relative paths stay scoped

Implementation constraints

  • Resolve paths before opening files.

Verification to include

  • Write a valid nested fixture
  • Reject parent-directory and drive paths

Deliverables

  • Manifest path validator

Rollout and recovery

Reject new manifests until path validation is restored.

Value of the work

For the engineer: Practice mobile file lifecycles and background state recovery.

For the team: Inspect predictable resource usage and truthful download status.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.