diff options
Diffstat (limited to 'spec/services/protected_tags/create_service_spec.rb')
-rw-r--r-- | spec/services/protected_tags/create_service_spec.rb | 39 |
1 files changed, 38 insertions, 1 deletions
diff --git a/spec/services/protected_tags/create_service_spec.rb b/spec/services/protected_tags/create_service_spec.rb index e85a43eb51c..3d06cc9fb6c 100644 --- a/spec/services/protected_tags/create_service_spec.rb +++ b/spec/services/protected_tags/create_service_spec.rb @@ -7,17 +7,54 @@ RSpec.describe ProtectedTags::CreateService do let(:user) { project.owner } let(:params) do { - name: 'master', + name: name, create_access_levels_attributes: [{ access_level: Gitlab::Access::MAINTAINER }] } end describe '#execute' do + let(:name) { 'tag' } + subject(:service) { described_class.new(project, user, params) } it 'creates a new protected tag' do expect { service.execute }.to change(ProtectedTag, :count).by(1) expect(project.protected_tags.last.create_access_levels.map(&:access_level)).to eq([Gitlab::Access::MAINTAINER]) end + + context 'when name has escaped HTML' do + let(:name) { 'tag->test' } + + it 'creates the new protected tag matching the unescaped version' do + expect { service.execute }.to change(ProtectedTag, :count).by(1) + expect(project.protected_tags.last.name).to eq('tag->test') + end + + context 'and name contains HTML tags' do + let(:name) { '<b>tag</b>' } + + it 'creates the new protected tag with sanitized name' do + expect { service.execute }.to change(ProtectedTag, :count).by(1) + expect(project.protected_tags.last.name).to eq('tag') + end + + context 'and contains unsafe HTML' do + let(:name) { '<script>alert('foo');</script>' } + + it 'does not create the new protected tag' do + expect { service.execute }.not_to change(ProtectedTag, :count) + end + end + end + + context 'when name contains unescaped HTML tags' do + let(:name) { '<b>tag</b>' } + + it 'creates the new protected tag with sanitized name' do + expect { service.execute }.to change(ProtectedTag, :count).by(1) + expect(project.protected_tags.last.name).to eq('tag') + end + end + end end end |