|
@@ -22,30 +22,34 @@ func Test_IsSameSiteURLPath(t *testing.T) {
|
|
|
{"http://github.com", false},
|
|
{"http://github.com", false},
|
|
|
{"https://github.com", false},
|
|
{"https://github.com", false},
|
|
|
{"/\\github.com", false},
|
|
{"/\\github.com", false},
|
|
|
|
|
+
|
|
|
{"/admin", true},
|
|
{"/admin", true},
|
|
|
{"/user/repo", true},
|
|
{"/user/repo", true},
|
|
|
}
|
|
}
|
|
|
|
|
+
|
|
|
for _, tc := range testCases {
|
|
for _, tc := range testCases {
|
|
|
So(IsSameSiteURLPath(tc.url), ShouldEqual, tc.expect)
|
|
So(IsSameSiteURLPath(tc.url), ShouldEqual, tc.expect)
|
|
|
}
|
|
}
|
|
|
})
|
|
})
|
|
|
}
|
|
}
|
|
|
|
|
|
|
|
-func Test_SanitizePath(t *testing.T) {
|
|
|
|
|
- Convey("Sanitize malicious user-defined path", t, func() {
|
|
|
|
|
|
|
+func Test_IsMaliciousPath(t *testing.T) {
|
|
|
|
|
+ Convey("Detects malicious path", t, func() {
|
|
|
testCases := []struct {
|
|
testCases := []struct {
|
|
|
path string
|
|
path string
|
|
|
- expect string
|
|
|
|
|
|
|
+ expect bool
|
|
|
}{
|
|
}{
|
|
|
- {"../../../../../../../../../data/gitote/data/sessions/a/9/a9f0ab6c3ef63dd8", "data/gitote/data/sessions/a/9/a9f0ab6c3ef63dd8"},
|
|
|
|
|
- {"data/gitote/../../../../../../../../../data/sessions/a/9/a9f0ab6c3ef63dd8", "data/gitote/data/sessions/a/9/a9f0ab6c3ef63dd8"},
|
|
|
|
|
- {"..\\..\\..\\..\\..\\..\\..\\..\\..\\data\\gitote\\data\\sessions\\a\\9\\a9f0ab6c3ef63dd8", "data\\gitote\\data\\sessions\\a\\9\\a9f0ab6c3ef63dd8"},
|
|
|
|
|
- {"data\\gitote\\..\\..\\..\\..\\..\\..\\..\\..\\..\\data\\sessions\\a\\9\\a9f0ab6c3ef63dd8", "data\\gitote\\data\\sessions\\a\\9\\a9f0ab6c3ef63dd8"},
|
|
|
|
|
- {"data/sessions/a/9/a9f0ab6c3ef63dd8", "data/sessions/a/9/a9f0ab6c3ef63dd8"},
|
|
|
|
|
- {"data\\sessions\\a\\9\\a9f0ab6c3ef63dd8", "data\\sessions\\a\\9\\a9f0ab6c3ef63dd8"},
|
|
|
|
|
|
|
+ {"../../../../../../../../../data/gitote/data/sessions/a/9/a9f0ab6c3ef63dd8", true},
|
|
|
|
|
+ {"..\\/..\\/../data/gitote/data/sessions/a/9/a9f0ab6c3ef63dd8", true},
|
|
|
|
|
+ {"data/gitote/../../../../../../../../../data/sessions/a/9/a9f0ab6c3ef63dd8", true},
|
|
|
|
|
+ {"..\\..\\..\\..\\..\\..\\..\\..\\..\\data\\gitote\\data\\sessions\\a\\9\\a9f0ab6c3ef63dd8", true},
|
|
|
|
|
+ {"data\\gitote\\..\\..\\..\\..\\..\\..\\..\\..\\..\\data\\sessions\\a\\9\\a9f0ab6c3ef63dd8", true},
|
|
|
|
|
+
|
|
|
|
|
+ {"data/sessions/a/9/a9f0ab6c3ef63dd8", false},
|
|
|
|
|
+ {"data\\sessions\\a\\9\\a9f0ab6c3ef63dd8", false},
|
|
|
}
|
|
}
|
|
|
for _, tc := range testCases {
|
|
for _, tc := range testCases {
|
|
|
- So(SanitizePath(tc.path), ShouldEqual, tc.expect)
|
|
|
|
|
|
|
+ So(IsMaliciousPath(tc.path), ShouldEqual, tc.expect)
|
|
|
}
|
|
}
|
|
|
})
|
|
})
|
|
|
}
|
|
}
|