diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Resolve submodule links from `.gitmodules`
Diffstat (limited to '')
-rwxr-xr-xtests/t0200-security.sh41
1 file changed, 40 insertions, 1 deletion
diff --git a/tests/t0200-security.sh b/tests/t0200-security.sh
index f475301..8fce5f4 100755
--- a/tests/t0200-security.sh
+++ b/tests/t0200-security.sh
@@ -277,7 +277,7 @@ test_expect_success 'a surplus conversion is shown literally, not filled' '
grep "href=./m/submod/[0-9a-f]*/%s/%s/" tmp
'
-test_expect_success 'a well-formed module-link still takes path and sha1' '
+test_expect_success 'a well-formed module-link still takes name and sha1' '
{
echo "virtual-root=/" &&
echo "cache-size=0" &&
@@ -316,4 +316,43 @@ test_expect_success 'a doubled percent in a module-link renders as one' '
grep "href=./m/submod/%/$sub." tmp
'
+# The .gitmodules file is commit-controlled content, so a derived link may
+# carry any scheme and any byte an author can commit. Only http and https
+# may reach an href, and everything lands attribute-escaped.
+test_expect_success 'set up a hostile .gitmodules' '
+ (
+ cd repos/modlink &&
+ sub=$(git rev-parse HEAD) &&
+ git update-index --add --cacheinfo 160000,$sub,quoted &&
+ cat >.gitmodules <<-EOF &&
+ [submodule "submod"]
+ path = submod
+ url = javascript:alert(1)
+ [submodule "quoted"]
+ path = quoted
+ url = https://example.com/x'\''><script>alert(1)</script>
+ EOF
+ git add .gitmodules &&
+ git commit -m hostile
+ ) &&
+ {
+ echo "virtual-root=/" &&
+ echo "cache-size=0" &&
+ echo "enable-gitmodules-links=1" &&
+ echo "repo.url=modlink" &&
+ echo "repo.path=$PWD/repos/modlink/.git"
+ } >modlinkgmrc
+'
+
+test_expect_success 'a javascript url never reaches an href' '
+ CGIT_CONFIG="$PWD/modlinkgmrc" QUERY_STRING="url=modlink/tree/" cgit >tmp &&
+ ! grep "href=.javascript:" tmp &&
+ grep "class=.ls-mod. title=.javascript:alert(1).>submod</span>" tmp
+'
+
+test_expect_success 'a quote in a web url cannot break out of the href' '
+ ! grep "<script>alert" tmp &&
+ grep "href=.https://example.com/x&#x27;&gt;&lt;script&gt;" tmp
+'
+
test_done