diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Replace the browser markdown renderer with a filter
The readme is now escaped plain text unless `about-filter` points at
the new `about-render.lua`, which renders markdown, man pages and plain
text server-side. `enable-markdown` goes away with the renderer.
Diffstat (limited to '')
| -rw-r--r-- | tests/t0200-security.sh | 4 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 2 insertions, 2 deletions
diff --git a/tests/t0200-security.sh b/tests/t0200-security.sh index 83cdbfd..425708e 100644 --- a/tests/t0200-security.sh +++ b/tests/t0200-security.sh @@ -73,7 +73,7 @@ test_expect_success 'a small blob is still served' ' ' # --- Readme rendering escapes untrusted repository content ------------------ -test_expect_success 'markdown readme is escaped and marked for the client' ' +test_expect_success 'markdown readme without a filter is escaped as plain text' ' { echo "virtual-root=/" && echo "cache-size=0" && @@ -82,7 +82,7 @@ test_expect_success 'markdown readme is escaped and marked for the client' ' echo "repo.readme=master:README.md" } >secmdrc && CGIT_CONFIG="$PWD/secmdrc" QUERY_STRING="url=md/about/" cgit >tmp && - grep "data-markdown" tmp && + grep "pre class=.plaintext." tmp && grep "<script>" tmp && ! grep "<script>alert(1)</script>" tmp ' |
