Jim Manico wrote:
> The getValidFileName method does not validate that the file exists
> within a specified safe parent directory.  This protection is provided
> in the getValidDirectoryPath method.  This seems like a critical
> vulnerability to protect against for filePaths....
> How about adding a new getValidFilePath method that provides this
> protection?
> You like?

Yes, I like, but IIRC, I think this is one of those places where
symbolic links can bite you in the @rse.  I think Java returns the
physical path rather than the logical path.

