You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
forgejo/integrations
zeripath bbffcc3aec
Multiple Escaping Improvements (#17551)
There are multiple places where Gitea does not properly escape URLs that it is building and there are multiple places where it builds urls when there is already a simpler function available to use this.
    
This is an extensive PR attempting to fix these issues.

1. The first commit in this PR looks through all href, src and links in the Gitea codebase and has attempted to catch all the places where there is potentially incomplete escaping.
2. Whilst doing this we will prefer to use functions that create URLs over recreating them by hand.
3. All uses of strings should be directly escaped - even if they are not currently expected to contain escaping characters. The main benefit to doing this will be that we can consider relaxing the constraints on user names and reponames in future. 
4. The next commit looks at escaping in the wiki and re-considers the urls that are used there. Using the improved escaping here wiki files containing '/'. (This implementation will currently still place all of the wiki files the root directory of the repo but this would not be difficult to change.)
5. The title generation in feeds is now properly escaped.
6. EscapePound is no longer needed - urls should be PathEscaped / QueryEscaped as necessary but then re-escaped with Escape when creating html with locales Signed-off-by: Andrew Thornton <art27@cantab.net>

Signed-off-by: Andrew Thornton <art27@cantab.net>
3 years ago
..
gitea-repositories-meta Add an api endpoint to fetch git notes (#15373) (#16649) 3 years ago
migration-test Rename db Engines related functions (#17481) 3 years ago
README.md Fix various documentation, user-facing, and source comment typos (#16367) 3 years ago
README_ZH.md Bump `postgres` and `mysql` versions (#15710) 3 years ago
admin_user_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_admin_org_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_admin_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_branch_test.go Fix Benchmark tests, remove a broken one & add two new (#15250) 3 years ago
api_comment_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_fork_test.go Fix "data race" in testlogger (#9159) 5 years ago
api_gpg_keys_test.go Add option to provide signature for a token to verify key ownership (#14054) 3 years ago
api_helper_for_declarative_test.go refactor: move from io/ioutil to io and os package (#17109) 3 years ago
api_issue_label_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_issue_milestone_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_issue_reaction_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_issue_stopwatch_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_issue_subscription_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_issue_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_issue_tracked_time_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_keys_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_nodeinfo_test.go api: integration test for nodeinfo (#17346) 3 years ago
api_notification_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_oauth2_apps_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_org_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_private_serv_test.go Add integration tests for private.NoServCommand and private.ServCommand (#17456) 3 years ago
api_pull_commits_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_pull_review_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_pull_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_releases_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_edit_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_file_create_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_file_delete_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_file_helpers.go Fix Benchmark tests, remove a broken one & add two new (#15250) 3 years ago
api_repo_file_update_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_get_contents_list_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_get_contents_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_git_blobs_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_git_commits_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_git_hook_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_git_notes_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_git_ref_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_git_tags_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_git_trees_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_languages_test.go give gitea time to calculate language stats (#11812) 4 years ago
api_repo_lfs_locks_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_lfs_migrate_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_lfs_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_raw_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_tags_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_teams_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_repo_topic_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_settings_test.go Make mirror feature more configurable (#16957) 3 years ago
api_team_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_team_user_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_token_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_user_email_test.go Always store primary email address into email_address table and also the state (#15956) 3 years ago
api_user_heatmap_test.go Fix heatmap test (#17381) 3 years ago
api_user_org_perm_test.go [API] Add endpount to get user org permissions (#17232) 3 years ago
api_user_orgs_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_user_search_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
api_wiki_test.go Add API to get/edit wiki (#17278) 3 years ago
attachment_test.go Add size to Save function (#15264) 3 years ago
auth_ldap_test.go Refactor: Move login out of models (#16199) 3 years ago
benchmarks_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
branches_test.go Frontend refactor, PascalCase to camelCase, remove unused code (#17365) 3 years ago
change_default_branch_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
cmd_keys_test.go Completely quote AppPath and CustomConf paths (#12955) 4 years ago
compare_test.go Prevent NPE on invalid diff (#17197) 3 years ago
cors_test.go Fix "data race" in testlogger (#9159) 5 years ago
create_no_session_test.go refactor: move from io/ioutil to io and os package (#17109) 3 years ago
delete_user_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
download_test.go Support custom mime type mapping for text files (#16304) 3 years ago
editor_test.go Add golangci (#6418) 5 years ago
empty_repo_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
eventsource_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
explore_repos_test.go Fix "data race" in testlogger (#9159) 5 years ago
git_clone_wiki_test.go refactor: move from io/ioutil to io and os package (#17109) 3 years ago
git_helper_for_declarative_test.go Fix ipv6 parsing for builtin ssh server (#17561) 3 years ago
git_smart_http_test.go refactor: move from io/ioutil to io and os package (#17109) 3 years ago
git_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
goget_test.go Return go-get info on subdirs (#15642) 3 years ago
gpg_git_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
html_helper.go Frontend refactor, PascalCase to camelCase, remove unused code (#17365) 3 years ago
integration_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
issue_test.go Multiple Escaping Improvements (#17551) 3 years ago
lfs_getobject_test.go refactor: move from io/ioutil to io and os package (#17109) 3 years ago
lfs_local_endpoint_test.go refactor: move from io/ioutil to io and os package (#17109) 3 years ago
links_test.go Multiple Escaping Improvements (#17551) 3 years ago
migrate_test.go Move migrations into services and base into modules/migration (#17663) 3 years ago
mirror_pull_test.go Move migrations into services and base into modules/migration (#17663) 3 years ago
mirror_push_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
mssql.ini.tmpl Use immediate queues in integration tests and ensure that immediate (#16927) 3 years ago
mysql.ini.tmpl Use immediate queues in integration tests and ensure that immediate (#16927) 3 years ago
mysql8.ini.tmpl Use immediate queues in integration tests and ensure that immediate (#16927) 3 years ago
nonascii_branches_test.go Multiple Escaping Improvements (#17551) 3 years ago
oauth_test.go refactor: move from io/ioutil to io and os package (#17109) 3 years ago
org_count_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
org_test.go Ensure that restricted users can access repos for which they are members (#17460) 3 years ago
pgsql.ini.tmpl Use immediate queues in integration tests and ensure that immediate (#16927) 3 years ago
private-testing.key Fix verification of subkeys of default gpg key (#11713) 4 years ago
privateactivity_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
pull_compare_test.go Fix "data race" in testlogger (#9159) 5 years ago
pull_create_test.go Frontend refactor, PascalCase to camelCase, remove unused code (#17365) 3 years ago
pull_merge_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
pull_review_test.go Fix "data race" in testlogger (#9159) 5 years ago
pull_status_test.go Make manual merge autodetection optional and add manual merge as merge method (#12543) 3 years ago
pull_update_test.go Move some functions into services/repository (#17660) 3 years ago
release_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
rename_branch_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
repo_activity_test.go Fix activity count in TestRepoActivity (#9959) 5 years ago
repo_branch_test.go Redirect on bad CSRF instead of presenting bad page (#14937) 3 years ago
repo_commits_search_test.go Make TestCreateBranch and TestRepoCommitsSearch less noisy (#13471) 4 years ago
repo_commits_test.go Add an abstract json layout to make it's easier to change json library (#16528) 3 years ago
repo_fork_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
repo_generate_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
repo_migrate_test.go Add a migrate service type switch page (#12697) 4 years ago
repo_search_test.go Make Repo Code Indexer an Unique Queue (#17515) 3 years ago
repo_tag_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
repo_test.go Fixed assert statements. (#16089) 3 years ago
repo_watch_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
repofiles_delete_test.go Decouple unit test code from business code (#17623) 3 years ago
repofiles_update_test.go prefer NoError/Error over Nil/NotNil (#12271) 4 years ago
setting_test.go Add a /user/login landing page option (#9622) 5 years ago
signin_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
signout_test.go Logout POST action (#10582) 4 years ago
signup_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
sqlite.ini.tmpl Use immediate queues in integration tests and ensure that immediate (#16927) 3 years ago
ssh_key_test.go refactor: move from io/ioutil to io and os package (#17109) 3 years ago
testlogger.go Ensure that the testlogger has its final test removal safely (#16907) 3 years ago
timetracking_test.go Remove JS globals related to timetracking and due date (#13921) 4 years ago
user_avatar_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
user_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago
version_test.go Fix "data race" in testlogger (#9159) 5 years ago
view_test.go Display SVG files as images instead of text (#14101) 4 years ago
xss_test.go Decouple unit test, remove intermediate `unittestbridge` package (#17662) 3 years ago

README.md

Integrations tests

Integration tests can be run with make commands for the appropriate backends, namely:

make test-mysql
make test-pgsql
make test-sqlite

Make sure to perform a clean build before running tests:

make clean build

Run all tests via local drone

drone exec --local --build-event "pull_request"

Run sqlite integrations tests

Start tests

make test-sqlite

Run mysql integrations tests

Setup a mysql database inside docker

docker run -e "MYSQL_DATABASE=test" -e "MYSQL_ALLOW_EMPTY_PASSWORD=yes" -p 3306:3306 --rm --name mysql mysql:latest #(just ctrl-c to stop db and clean the container)
docker run -p 9200:9200 -p 9300:9300 -e "discovery.type=single-node" --rm --name elasticsearch elasticsearch:7.6.0 #(in a second terminal, just ctrl-c to stop db and clean the container)

Start tests based on the database container

TEST_MYSQL_HOST=localhost:3306 TEST_MYSQL_DBNAME=test TEST_MYSQL_USERNAME=root TEST_MYSQL_PASSWORD='' make test-mysql

Run pgsql integrations tests

Setup a pgsql database inside docker

docker run -e "POSTGRES_DB=test" -p 5432:5432 --rm --name pgsql postgres:latest #(just ctrl-c to stop db and clean the container)

Start tests based on the database container

TEST_PGSQL_HOST=localhost:5432 TEST_PGSQL_DBNAME=test TEST_PGSQL_USERNAME=postgres TEST_PGSQL_PASSWORD=postgres make test-pgsql

Run mssql integrations tests

Setup a mssql database inside docker

docker run -e "ACCEPT_EULA=Y" -e "MSSQL_PID=Standard" -e "SA_PASSWORD=MwantsaSecurePassword1" -p 1433:1433 --rm --name mssql microsoft/mssql-server-linux:latest #(just ctrl-c to stop db and clean the container)

Start tests based on the database container

TEST_MSSQL_HOST=localhost:1433 TEST_MSSQL_DBNAME=gitea_test TEST_MSSQL_USERNAME=sa TEST_MSSQL_PASSWORD=MwantsaSecurePassword1 make test-mssql

Running individual tests

Example command to run GPG test:

For sqlite:

make test-sqlite#GPG

For other databases(replace MSSQL to MYSQL, MYSQL8, PGSQL):

TEST_MSSQL_HOST=localhost:1433 TEST_MSSQL_DBNAME=test TEST_MSSQL_USERNAME=sa TEST_MSSQL_PASSWORD=MwantsaSecurePassword1 make test-mssql#GPG

Setting timeouts for declaring long-tests and long-flushes

We appreciate that some testing machines may not be very powerful and the default timeouts for declaring a slow test or a slow clean-up flush may not be appropriate.

You can either:

  • Within the test ini file set the following section:
[integration-tests]
SLOW_TEST = 10s ; 10s is the default value
SLOW_FLUSH = 5S ; 5s is the default value
  • Set the following environment variables:
GITEA_SLOW_TEST_TIME="10s" GITEA_SLOW_FLUSH_TIME="5s" make test-sqlite