# path-join-safe

> Join pathes, return undefined if resulting path is not inside of the first path.

Latest version **1.0.0** (published 2017-05-23) · ISC license · 0 weekly downloads

## Install

```sh
npm install path-join-safe
pnpm add path-join-safe
yarn add path-join-safe
bun add path-join-safe
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.0.0 |
| Published | 2017-05-23 |
| First published | 2017-05-23 |
| Weekly downloads | 0 |
| License | ISC |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 0 |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Author | grabantot |
| Maintainers | grabantot |
| Keywords | path, join, safe, restrict, directory, unsafe, subdirectory, folder |

## Links

- npm: https://www.npmjs.com/package/path-join-safe
- npm.io page: https://npm.io/package/path-join-safe

## Alternatives

- [base64url](https://npm.io/package/base64url.md) — 6.1M weekly downloads
- [get-installed-path](https://npm.io/package/get-installed-path.md) — 502.9K weekly downloads
- [@uppy/url](https://npm.io/package/@uppy/url.md) — 185.8K weekly downloads
- [@d3fc/d3fc-shape](https://npm.io/package/@d3fc/d3fc-shape.md) — 16.2K weekly downloads
- [localizer](https://npm.io/package/localizer.md) — 226 weekly downloads

## Recent versions

- 1.0.0 (latest) — 2017-05-23

## README

# path-join-safe
Join pathes, return undefined if the resulting path is not within the path passed as the first argument.

## Usage
The module extends node's `path.posix` and `path.win32` with `joinSafe` methods, so it can be used like this:
```
const path = require('path')
/*const joinSafe = */require('path-join-safe') //joinSafe == path.joinSafe
let safe_path = path.posix.joinSafe('a/b/c', 'd') //returns 'a/b/c/d'
let unsafe_path = path.joinSafe('a/b/c', '..') //returns undefined
```

---
_Source: https://npm.io/package/path-join-safe · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
