summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorRobert Speicher <rspeicher@gmail.com>2016-04-09 18:40:15 -0400
committerRobert Speicher <rspeicher@gmail.com>2016-04-09 18:50:21 -0400
commit5ffa8f057095fb2fe12a60ffa0dd3a611d2f1aeb (patch)
tree9120416e842cd78efcf96127fe7b2fc84cc0d331
parent600b94cd8bdf767e3f5ae4b21af73858a0055a7c (diff)
downloadgitlab-ce-rs-trailing-slash-in-search.tar.gz
Escape the query argument provided to `git grep` by `search_files`rs-trailing-slash-in-search
Closes #14963.
-rw-r--r--app/models/repository.rb2
-rw-r--r--spec/models/repository_spec.rb6
2 files changed, 7 insertions, 1 deletions
diff --git a/app/models/repository.rb b/app/models/repository.rb
index 8dead3a5884..090cccd2c72 100644
--- a/app/models/repository.rb
+++ b/app/models/repository.rb
@@ -795,7 +795,7 @@ class Repository
def search_files(query, ref)
offset = 2
- args = %W(#{Gitlab.config.git.bin_path} grep -i -I -n --before-context #{offset} --after-context #{offset} -e #{query} #{ref || root_ref})
+ args = %W(#{Gitlab.config.git.bin_path} grep -i -I -n --before-context #{offset} --after-context #{offset} -e #{Regexp.escape(query)} #{ref || root_ref})
Gitlab::Popen.popen(args, path_to_repo).first.scrub.split(/^--$/)
end
diff --git a/spec/models/repository_spec.rb b/spec/models/repository_spec.rb
index 4e49c413f23..bce30aafc4c 100644
--- a/spec/models/repository_spec.rb
+++ b/spec/models/repository_spec.rb
@@ -94,6 +94,12 @@ describe Repository, models: true do
it { is_expected.to be_an Array }
+ it 'regex-escapes the query string' do
+ results = repository.search_files("test\\", 'master')
+
+ expect(results.first).not_to start_with('fatal:')
+ end
+
describe 'result' do
subject { results.first }