diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Resolve submodule links from `.gitmodules`
Diffstat (limited to '')
| -rwxr-xr-x | tests/t0200-security.sh | 41 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 40 insertions, 1 deletion
diff --git a/tests/t0200-security.sh b/tests/t0200-security.sh index f475301..8fce5f4 100755 --- a/tests/t0200-security.sh +++ b/tests/t0200-security.sh @@ -277,7 +277,7 @@ test_expect_success 'a surplus conversion is shown literally, not filled' ' grep "href=./m/submod/[0-9a-f]*/%s/%s/" tmp ' -test_expect_success 'a well-formed module-link still takes path and sha1' ' +test_expect_success 'a well-formed module-link still takes name and sha1' ' { echo "virtual-root=/" && echo "cache-size=0" && @@ -316,4 +316,43 @@ test_expect_success 'a doubled percent in a module-link renders as one' ' grep "href=./m/submod/%/$sub." tmp ' +# The .gitmodules file is commit-controlled content, so a derived link may +# carry any scheme and any byte an author can commit. Only http and https +# may reach an href, and everything lands attribute-escaped. +test_expect_success 'set up a hostile .gitmodules' ' + ( + cd repos/modlink && + sub=$(git rev-parse HEAD) && + git update-index --add --cacheinfo 160000,$sub,quoted && + cat >.gitmodules <<-EOF && + [submodule "submod"] + path = submod + url = javascript:alert(1) + [submodule "quoted"] + path = quoted + url = https://example.com/x'\''><script>alert(1)</script> + EOF + git add .gitmodules && + git commit -m hostile + ) && + { + echo "virtual-root=/" && + echo "cache-size=0" && + echo "enable-gitmodules-links=1" && + echo "repo.url=modlink" && + echo "repo.path=$PWD/repos/modlink/.git" + } >modlinkgmrc +' + +test_expect_success 'a javascript url never reaches an href' ' + CGIT_CONFIG="$PWD/modlinkgmrc" QUERY_STRING="url=modlink/tree/" cgit >tmp && + ! grep "href=.javascript:" tmp && + grep "class=.ls-mod. title=.javascript:alert(1).>submod</span>" tmp +' + +test_expect_success 'a quote in a web url cannot break out of the href' ' + ! grep "<script>alert" tmp && + grep "href=.https://example.com/x'><script>" tmp +' + test_done |
