diff options
Diffstat (limited to 'spec/views/projects/empty.html.haml_spec.rb')
-rw-r--r-- | spec/views/projects/empty.html.haml_spec.rb | 15 |
1 files changed, 15 insertions, 0 deletions
diff --git a/spec/views/projects/empty.html.haml_spec.rb b/spec/views/projects/empty.html.haml_spec.rb index 416dfc10174..6077dda3c98 100644 --- a/spec/views/projects/empty.html.haml_spec.rb +++ b/spec/views/projects/empty.html.haml_spec.rb @@ -25,6 +25,21 @@ RSpec.describe 'projects/empty' do expect(rendered).to have_content("git clone") end + + context 'when default branch name contains special shell characters' do + let(:branch_name) { ';rm -rf /' } + + before do + allow(project).to receive(:default_branch_or_main).and_return(branch_name) + end + + it 'escapes the default branch name' do + render + + expect(rendered).not_to have_content(branch_name) + expect(rendered).to have_content(branch_name.shellescape) + end + end end context 'when user can not push code on the project' do |