Security audit finding SEC-IPC-01 (parameter part). The username is
passed to game_setup/game_start/server_start batch scripts as a quoted
`cmd.exe` argument. Quoting protects the launcher's own command line,
but batch scripts expand `%~4` textually into their own statements, so
a name such as `foo & calc` would run `calc` from `set NAME=%~4`. Since
the setup script runs elevated, that matters even though the value is
the local user's own input.
`sanitize_username` previously removed control characters, `"` and
`%`; it now also removes `& | < > ^`. Spaces, punctuation such as `!`
and non-ASCII letters remain allowed so ordinary gamer tags are not
mangled. The audit's stricter `[A-Za-z0-9_-]` allowlist was rejected
for that reason.
The elevated execution of catalog scripts itself is intentional: the
shared games need administrator setup and the archives that carry the
scripts are BLAKE3-verified against the bundled catalog.
Test plan: `just test` (extended sanitizer test).
Claude-Session: https://claude.ai/code/session_017C3Nbgwpdm3YNwZhhFLHwg