diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Replace the browser markdown renderer with a filter
The readme is now escaped plain text unless `about-filter` points at the new `about-render.lua`, which renders markdown, man pages and plain text server-side. `enable-markdown` goes away with the renderer.
Diffstat (limited to '')
-rw-r--r--tests/t0200-security.sh4
1 file changed, 2 insertions, 2 deletions
diff --git a/tests/t0200-security.sh b/tests/t0200-security.sh
index 83cdbfd..425708e 100644
--- a/tests/t0200-security.sh
+++ b/tests/t0200-security.sh
@@ -73,7 +73,7 @@ test_expect_success 'a small blob is still served' '
'
# --- Readme rendering escapes untrusted repository content ------------------
-test_expect_success 'markdown readme is escaped and marked for the client' '
+test_expect_success 'markdown readme without a filter is escaped as plain text' '
{
echo "virtual-root=/" &&
echo "cache-size=0" &&
@@ -82,7 +82,7 @@ test_expect_success 'markdown readme is escaped and marked for the client' '
echo "repo.readme=master:README.md"
} >secmdrc &&
CGIT_CONFIG="$PWD/secmdrc" QUERY_STRING="url=md/about/" cgit >tmp &&
- grep "data-markdown" tmp &&
+ grep "pre class=.plaintext." tmp &&
grep "&lt;script&gt;" tmp &&
! grep "<script>alert(1)</script>" tmp
'