diff options
author | John Jarvis <jarv@gitlab.com> | 2019-01-01 20:38:30 +0000 |
---|---|---|
committer | John Jarvis <jarv@gitlab.com> | 2019-01-01 20:38:30 +0000 |
commit | 8f461ef779187018ddac59dbaccafe01c493e463 (patch) | |
tree | 8801628216033c7025d86c894939da2ca8011755 /spec/controllers/snippets_controller_spec.rb | |
parent | c684dd63e29d97ccf5cabd81f4abfed8d1bd5cec (diff) | |
parent | ed0d691e0dfba54cd8f03706afd011afe4063a7a (diff) | |
download | gitlab-ce-8f461ef779187018ddac59dbaccafe01c493e463.tar.gz |
Merge branch 'security-48259-private-snippet' into 'master'
[master] Prevent private snippet from being embeddable
See merge request gitlab/gitlabhq!2692
Diffstat (limited to 'spec/controllers/snippets_controller_spec.rb')
-rw-r--r-- | spec/controllers/snippets_controller_spec.rb | 19 |
1 files changed, 19 insertions, 0 deletions
diff --git a/spec/controllers/snippets_controller_spec.rb b/spec/controllers/snippets_controller_spec.rb index d2a56518f65..d762531da7e 100644 --- a/spec/controllers/snippets_controller_spec.rb +++ b/spec/controllers/snippets_controller_spec.rb @@ -80,6 +80,12 @@ describe SnippetsController do expect(assigns(:snippet)).to eq(personal_snippet) expect(response).to have_gitlab_http_status(200) end + + it 'responds with status 404 when embeddable content is requested' do + get :show, id: personal_snippet.to_param, format: :js + + expect(response).to have_gitlab_http_status(404) + end end end @@ -106,6 +112,12 @@ describe SnippetsController do expect(assigns(:snippet)).to eq(personal_snippet) expect(response).to have_gitlab_http_status(200) end + + it 'responds with status 404 when embeddable content is requested' do + get :show, id: personal_snippet.to_param, format: :js + + expect(response).to have_gitlab_http_status(404) + end end context 'when not signed in' do @@ -131,6 +143,13 @@ describe SnippetsController do expect(assigns(:snippet)).to eq(personal_snippet) expect(response).to have_gitlab_http_status(200) end + + it 'responds with status 200 when embeddable content is requested' do + get :show, id: personal_snippet.to_param, format: :js + + expect(assigns(:snippet)).to eq(personal_snippet) + expect(response).to have_gitlab_http_status(200) + end end context 'when not signed in' do |