Audiobook Studio 2.0 docs

Paths & Security

User-influenced paths are treated as hostile input. Studio contains them with dedicated helpers.

At a glance
  • safe_join / secure_join_flat / find_secure_file.
  • A containment pattern for all path building.
  • Aligned with static analysis (CodeQL).

Containment

Never join user input into a path directly. The secure-join helpers keep resolved paths inside their intended root, blocking traversal.

Why it matters

Paths are an untrusted surface. Treating them consistently, and keeping aligned with CodeQL findings, prevents a whole class of vulnerabilities.