Escape the database path in the SQLite connection string (closes #55) #87

Merged
clawbot merged 1 commits from issue-55-escape-database-path into next 2026-10-04 15:13:20 +02:00
1 Commits
Author SHA1 Message Date
sneak c67e332ddc Escape the database path in the SQLite connection string (closes #55)
check / check (push) Failing after 1s
openDB put the path into the connection string unescaped, so a ? or #
in it ended the file name and a % started an escape: scan could
silently fill a database under a shortened name. The path now goes
through net/url as a file: URI. An absolute path gets an empty host and
a relative path none, because SQLite reads what follows file:// up to
the next slash as a host name. The path is not cleaned, so it stays
exactly what the operator gave.

A test runs scan, report and trees against such a file name given as an
absolute path, as one starting with //, and as a relative path, and
checks that only that file and its lock file exist afterwards.

Model: opus-5-5
2026-10-04 12:49:31 +00:00