From d466c1122b89625ef3ccec55d184f0aed8a61541 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sat, 8 Aug 2026 12:50:10 -1000 Subject: Bound the search and cache key a request can ask --- tests/t0201-limits.sh | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) (limited to 'tests/t0201-limits.sh') diff --git a/tests/t0201-limits.sh b/tests/t0201-limits.sh index a8dce62..72d8a23 100755 --- a/tests/t0201-limits.sh +++ b/tests/t0201-limits.sh @@ -43,6 +43,25 @@ test_expect_success 'set up limit fixtures' ' limitq() { CGIT_CONFIG="$PWD/limitrc" QUERY_STRING="$1" cgit; } +# --- A request cannot ask for an unbounded amount of matching --------------- +# The query is compared against every repository the index lists, so an +# enormous one would multiply out across the whole listing. It is clamped +# rather than rejected, so an ordinary query still narrows the page. +test_expect_success 'an enormous query is clamped, not rejected' ' + long=$(awk "BEGIN{s=\"\";for(i=0;i<4000;i++)s=s \"a\"; print s}") && + test ${#long} -eq 4000 && + cgit_query "q=$long" >tmp && + grep "" tmp && + longest=$(grep -o "aaaa*" tmp | awk "{print length}" | sort -n | tail -1) && + test "$longest" -eq 512 +' + +test_expect_success 'an ordinary query still filters the index' ' + cgit_query "q=foo" >tmp && + grep "foo" tmp && + ! grep ">bar<" tmp +' + # --- The refs page caps each section and links to the category pages -------- test_expect_success 'refs page lists max-ref-count branches and tags' ' limitq "url=limits/refs/" >tmp && -- cgit v2.8.0