summaryrefslogtreecommitdiff
path: root/spec
diff options
context:
space:
mode:
authorSean McGivern <sean@gitlab.com>2017-04-05 21:17:49 +0000
committerDJ Mountney <david@twkie.net>2017-04-05 15:58:52 -0700
commitc22e9d8b818d7fec96710a7deb47a84cbbbf41f0 (patch)
tree4bb3052d856be6ea032e85f488955995ec0311aa /spec
parent5f81898343cabd65a49dbbba9d7c00e06b0eca69 (diff)
downloadgitlab-ce-c22e9d8b818d7fec96710a7deb47a84cbbbf41f0.tar.gz
Merge branch 'open-redirect-fix-continue-to' into 'security'
Fix for open redirect vuln involving continue[to] params See merge request !2083
Diffstat (limited to 'spec')
-rw-r--r--spec/controllers/projects/imports_controller_spec.rb9
1 files changed, 8 insertions, 1 deletions
diff --git a/spec/controllers/projects/imports_controller_spec.rb b/spec/controllers/projects/imports_controller_spec.rb
index 7c75815f3c4..6724b474179 100644
--- a/spec/controllers/projects/imports_controller_spec.rb
+++ b/spec/controllers/projects/imports_controller_spec.rb
@@ -96,12 +96,19 @@ describe Projects::ImportsController do
}
end
- it 'redirects to params[:to]' do
+ it 'redirects to internal params[:to]' do
get :show, namespace_id: project.namespace.to_param, project_id: project, continue: params
expect(flash[:notice]).to eq params[:notice]
expect(response).to redirect_to params[:to]
end
+
+ it 'does not redirect to external params[:to]' do
+ params[:to] = "//google.com"
+
+ get :show, namespace_id: project.namespace.to_param, project_id: project, continue: params
+ expect(response).not_to redirect_to params[:to]
+ end
end
end