diff options
author | Winnie Hellmann <winnie@gitlab.com> | 2018-11-09 14:14:47 +0100 |
---|---|---|
committer | Winnie Hellmann <winnie@gitlab.com> | 2018-11-19 14:39:19 +0100 |
commit | 58161315dc26c5671a19e83c8b3ea92c9c347308 (patch) | |
tree | cd6ca52715b98e7cb570144a83580048952cf3b1 | |
parent | d88c471071e47fc0b3995056821c81d59a0de76b (diff) | |
download | gitlab-ce-58161315dc26c5671a19e83c8b3ea92c9c347308.tar.gz |
Add failing test for XSS in mermaid diagrams
(cherry picked from commit fdea799d37ae9ca3f5e80f191a55be543a79857a)
-rw-r--r-- | spec/features/issues/user_comments_on_issue_spec.rb | 12 | ||||
-rw-r--r-- | spec/features/markdown/mermaid_spec.rb | 2 |
2 files changed, 13 insertions, 1 deletions
diff --git a/spec/features/issues/user_comments_on_issue_spec.rb b/spec/features/issues/user_comments_on_issue_spec.rb index ba5b80ed04b..b4b9a589ba3 100644 --- a/spec/features/issues/user_comments_on_issue_spec.rb +++ b/spec/features/issues/user_comments_on_issue_spec.rb @@ -40,6 +40,18 @@ describe "User comments on issue", :js do expect(page.find('pre code').text).to eq code_block_content end + + it "does not render html content in mermaid" do + html_content = "<img onerror=location=`javascript\\u003aalert\\u0028document.domain\\u0029` src=x>" + mermaid_content = "graph LR\n B-->D(#{html_content});" + comment = "```mermaid\n#{mermaid_content}\n```" + + add_note(comment) + + wait_for_requests + + expect(page.find('svg.mermaid')).to have_content html_content + end end context "when editing comments" do diff --git a/spec/features/markdown/mermaid_spec.rb b/spec/features/markdown/mermaid_spec.rb index a25d701ee35..7008b361394 100644 --- a/spec/features/markdown/mermaid_spec.rb +++ b/spec/features/markdown/mermaid_spec.rb @@ -18,7 +18,7 @@ describe 'Mermaid rendering', :js do visit project_issue_path(project, issue) %w[A B C D].each do |label| - expect(page).to have_selector('svg foreignObject', text: label) + expect(page).to have_selector('svg text', text: label) end end end |