diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Gate html serving behind trust-scan-config
`enable-html-serving` makes the plain page send a repository file as text/html on the site's own origin, with no nosniff and no policy, so a scanned repository could switch it on from its git config or cgitrc without `trust-scan-config` and run script against every visitor. The warning for a key read from git config also named a null repository, because `repo->path` was set only after that file had been read.
Diffstat (limited to 'tests/t0303-robustness.sh')
-rwxr-xr-xtests/t0303-robustness.sh42
1 file changed, 39 insertions, 3 deletions
diff --git a/tests/t0303-robustness.sh b/tests/t0303-robustness.sh
index ea50eac..cb16957 100755
--- a/tests/t0303-robustness.sh
+++ b/tests/t0303-robustness.sh
@@ -1,8 +1,8 @@
#!/bin/sh
-# Regression tests from the September 2026 audit. Each case is a config,
-# repository or request that used to crash cgit, end it inside git, or hand
-# a visitor something other than what was asked for.
+# Regression tests from the audits of September and October 2026. Each case
+# is a config, repository or request that used to crash cgit, end it inside
+# git, or hand a visitor something other than what was asked for.
test_description='Check the audit regressions'
. ./setup.sh
@@ -112,6 +112,42 @@ test_expect_success 'a filesystem readme from a scanned repository is refused' '
grep "Ignoring readme in " err
'
+# A repository served as html runs its pages on the site's own origin, so
+# the switch waits on trust like the keys that place markup. The warning has
+# to name the repository, which it did not for a key read from git config.
+test_expect_success 'html serving from a scanned repository waits on trust' '
+ (
+ cd repos/rob &&
+ printf "<p>page</p>\n" >page.html &&
+ git add page.html &&
+ git commit -m html
+ ) &&
+ mkdir -p scan2 &&
+ git clone -q --bare repos/rob/.git scan2/c.git &&
+ git -C scan2/c.git config cgit.enable-html-serving 1 &&
+ {
+ echo "virtual-root=/" &&
+ echo "cache-size=0" &&
+ echo "enable-git-config=1" &&
+ echo "mimetype.html=text/html" &&
+ echo "scan-path=$PWD/scan2"
+ } >htmlrc &&
+ CGIT_CONFIG="$PWD/htmlrc" QUERY_STRING="url=c.git/plain/page.html" cgit >tmp 2>err &&
+ grep "^Content-Type: text/plain" tmp &&
+ grep "^X-Content-Type-Options: nosniff" tmp &&
+ grep "Ignoring enable-html-serving in $PWD/scan2/c.git/: trust-scan-config is not set" err
+'
+
+test_expect_success 'with trust-scan-config the same repository serves html' '
+ {
+ echo "trust-scan-config=1" &&
+ cat htmlrc
+ } >htmltrustrc &&
+ CGIT_CONFIG="$PWD/htmltrustrc" QUERY_STRING="url=c.git/plain/page.html" cgit >tmp &&
+ grep "^Content-Type: text/html" tmp &&
+ ! grep "^X-Content-Type-Options" tmp
+'
+
test_expect_success SYMLINKS 'a symlink cycle under the scan path is entered once' '
ln -s . scan/loop &&
CGIT_CONFIG="$PWD/gitcfgrc" QUERY_STRING="url=" cgit >tmp &&