request from directory . should drop forbidden error

This commit is contained in:
shortcutme 2017-10-04 12:48:48 +02:00
parent a2182e8a8d
commit 0f0f3894ff
No known key found for this signature in database
GPG key ID: 5B63BAE6CB9613AE

View file

@ -31,7 +31,7 @@ def wget(url):
class TestWeb:
def testFileSecurity(self, site_url):
assert "Not Found" in wget("%s/media/sites.json" % site_url)
assert "Not Found" in wget("%s/media/./sites.json" % site_url)
assert "Forbidden" in wget("%s/media/./sites.json" % site_url)
assert "Forbidden" in wget("%s/media/../config.py" % site_url)
assert "Forbidden" in wget("%s/media/1EU1tbG9oC1A8jz2ouVwGZyQ5asrNsE4Vr/../sites.json" % site_url)
assert "Forbidden" in wget("%s/media/1EU1tbG9oC1A8jz2ouVwGZyQ5asrNsE4Vr/..//sites.json" % site_url)