diff options
Diffstat (limited to 'spec/support/shared_examples/lib/gitlab/regex_shared_examples.rb')
-rw-r--r-- | spec/support/shared_examples/lib/gitlab/regex_shared_examples.rb | 8 |
1 files changed, 8 insertions, 0 deletions
diff --git a/spec/support/shared_examples/lib/gitlab/regex_shared_examples.rb b/spec/support/shared_examples/lib/gitlab/regex_shared_examples.rb new file mode 100644 index 00000000000..150741c6344 --- /dev/null +++ b/spec/support/shared_examples/lib/gitlab/regex_shared_examples.rb @@ -0,0 +1,8 @@ +# frozen_string_literal: true + +RSpec.shared_examples 'regex rejecting path traversal' do + it { is_expected.not_to match('a../b') } + it { is_expected.not_to match('a..%2fb') } + it { is_expected.not_to match('a%2e%2e%2fb') } + it { is_expected.not_to match('a%2e%2e/b') } +end |