diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Bound the search and cache key a request can ask
Diffstat (limited to '')
-rwxr-xr-xtests/t0201-limits.sh19
1 file changed, 19 insertions, 0 deletions
diff --git a/tests/t0201-limits.sh b/tests/t0201-limits.sh
index a8dce62..72d8a23 100755
--- a/tests/t0201-limits.sh
+++ b/tests/t0201-limits.sh
@@ -43,6 +43,25 @@ test_expect_success 'set up limit fixtures' '
limitq() { CGIT_CONFIG="$PWD/limitrc" QUERY_STRING="$1" cgit; }
+# --- A request cannot ask for an unbounded amount of matching ---------------
+# The query is compared against every repository the index lists, so an
+# enormous one would multiply out across the whole listing. It is clamped
+# rather than rejected, so an ordinary query still narrows the page.
+test_expect_success 'an enormous query is clamped, not rejected' '
+ long=$(awk "BEGIN{s=\"\";for(i=0;i<4000;i++)s=s \"a\"; print s}") &&
+ test ${#long} -eq 4000 &&
+ cgit_query "q=$long" >tmp &&
+ grep "</html>" tmp &&
+ longest=$(grep -o "aaaa*" tmp | awk "{print length}" | sort -n | tail -1) &&
+ test "$longest" -eq 512
+'
+
+test_expect_success 'an ordinary query still filters the index' '
+ cgit_query "q=foo" >tmp &&
+ grep "foo" tmp &&
+ ! grep ">bar<" tmp
+'
+
# --- The refs page caps each section and links to the category pages --------
test_expect_success 'refs page lists max-ref-count branches and tags' '
limitq "url=limits/refs/" >tmp &&