You've overlooked the critical call in the previous line:
def is_secure_path(path):
path = posixpath.normpath(path)
return not path.startswith(('/', '../'))
The call to `normpath` normalises the path, e.g. >>> normpath('./../foo')
'../foo'