[master] Resolve "[Security] Stored XSS via KaTeX"

This commit is contained in:
Constance Okoghenun 2019-01-24 14:41:42 +00:00 committed by Yorick Peterse
parent 7752864125
commit 645f7ee86b
No known key found for this signature in database
GPG key ID: EDD30D2BEB691AC9
2 changed files with 22 additions and 1 deletions

View file

@ -0,0 +1,5 @@
---
title: Fixed XSS content in KaTex links
merge_request:
author:
type: security

View file

@ -1,6 +1,8 @@
require 'spec_helper'
describe 'Math rendering', :js do
let!(:project) { create(:project, :public) }
it 'renders inline and display math correctly' do
description = <<~MATH
This math is inline $`a^2+b^2=c^2`$.
@ -11,7 +13,6 @@ describe 'Math rendering', :js do
```
MATH
project = create(:project, :public)
issue = create(:issue, project: project, description: description)
visit project_issue_path(project, issue)
@ -19,4 +20,19 @@ describe 'Math rendering', :js do
expect(page).to have_selector('.katex .mord.mathdefault', text: 'b')
expect(page).to have_selector('.katex-display .mord.mathdefault', text: 'b')
end
it 'only renders non XSS links' do
description = <<~MATH
This link is valid $`\\href{javascript:alert('xss');}{xss}`$.
This link is valid $`\\href{https://gitlab.com}{Gitlab}`$.
MATH
issue = create(:issue, project: project, description: description)
visit project_issue_path(project, issue)
expect(page).to have_selector('.katex-error', text: "\href{javascript:alert('xss');}{xss}")
expect(page).to have_selector('.katex-html a', text: 'Gitlab')
end
end