vendor/rack/test/spec_rack_directory.rb in relevance-castronaut-0.5.4 vs vendor/rack/test/spec_rack_directory.rb in relevance-castronaut-0.6.0
- old
+ new
@@ -43,9 +43,14 @@
specify "does not allow directory traversal" do
res = Rack::MockRequest.new(Rack::Lint.new(app)).
get("/cgi/../test")
res.should.be.forbidden
+
+ res = Rack::MockRequest.new(Rack::Lint.new(app)).
+ get("/cgi/%2E%2E/test")
+
+ res.should.be.forbidden
end
specify "404s if it can't find the file" do
res = Rack::MockRequest.new(Rack::Lint.new(app)).
get("/cgi/blubb")