External path fragments must remain within an intended root. Normalization alone does not establish authorization or prevent every symlink escape.
Before you start
You should know JavaScript promises, asynchronous errors and the distinction between a process and a request. When following a server example, identify the resource owner and the point where work completes. Try experiments locally with bounded input instead of assuming production traffic behaves like a single request.
The practical goal is to reason through this situation: Resolve a requested relative path and verify its relationship to the allowed directory. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.
Step-by-step walkthrough
Step 1: Use authorized identifiers
Prefer record IDs mapped to server-controlled paths over arbitrary user-supplied path strings.
Step 2: Check directory relationships
Resolve and compare actual path relationships rather than string prefixes such as /safe matching /safe-other.
Step 3: Account for filesystem behavior
Symlinks and races can escape assumptions established before opening. Match the protection to the platform and threat model.
Worked scenario
Resolve a requested relative path and verify its relationship to the allowed directory.
A download request for file 42 first checks ownership in the application database, then resolves the server-stored path. A normalized traversal string is still untrusted. Even a lexical containment check may not account for a symlink within the allowed directory, so path normalization is only one layer of the boundary.
Common mistake
Prefix-string checks can confuse sibling directories with shared names.
Verify the behavior
Test traversal, similarly prefixed sibling directories, symlinks and another user’s ID. Verify denial before file contents are exposed.
Interview exercise
Serve user-owned files safely.
Answer and reasoning
Validate ownership, constrain identifiers and account for symlinks and filesystem race conditions instead of trusting raw paths.
Continue learning
Compare the scenario with the Node.js interview questions and test your understanding with the Node.js MCQs. For terminology and implementation details, consult the reference material.