diff options
author | Sean McGivern <sean@gitlab.com> | 2017-04-05 21:17:49 +0000 |
---|---|---|
committer | DJ Mountney <david@twkie.net> | 2017-04-05 21:07:26 -0700 |
commit | d687f6436a14c8b36f1a560ee95222bb2d4fb63f (patch) | |
tree | c55f23c41b4afcf9590fd056c33a0c367fd40fc2 /spec/controllers | |
parent | b80653bb6aa8518e0a61e85cae4430928078c092 (diff) | |
download | gitlab-ce-d687f6436a14c8b36f1a560ee95222bb2d4fb63f.tar.gz |
Merge branch 'open-redirect-fix-continue-to' into 'security'
Fix for open redirect vuln involving continue[to] params
See merge request !2083
Diffstat (limited to 'spec/controllers')
-rw-r--r-- | spec/controllers/projects/imports_controller_spec.rb | 9 |
1 files changed, 8 insertions, 1 deletions
diff --git a/spec/controllers/projects/imports_controller_spec.rb b/spec/controllers/projects/imports_controller_spec.rb index 7c75815f3c4..6724b474179 100644 --- a/spec/controllers/projects/imports_controller_spec.rb +++ b/spec/controllers/projects/imports_controller_spec.rb @@ -96,12 +96,19 @@ describe Projects::ImportsController do } end - it 'redirects to params[:to]' do + it 'redirects to internal params[:to]' do get :show, namespace_id: project.namespace.to_param, project_id: project, continue: params expect(flash[:notice]).to eq params[:notice] expect(response).to redirect_to params[:to] end + + it 'does not redirect to external params[:to]' do + params[:to] = "//google.com" + + get :show, namespace_id: project.namespace.to_param, project_id: project, continue: params + expect(response).not_to redirect_to params[:to] + end end end |