test_ssi.py 4.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112
  1. from __future__ import unicode_literals
  2. import os
  3. from django.template import Context, Engine
  4. from django.test import SimpleTestCase, ignore_warnings
  5. from django.utils.deprecation import RemovedInDjango110Warning
  6. from ..utils import ROOT, setup
  7. @ignore_warnings(category=RemovedInDjango110Warning)
  8. class SsiTagTests(SimpleTestCase):
  9. # Test normal behavior
  10. @setup({'ssi01': '{%% ssi "%s" %%}' % os.path.join(
  11. ROOT, 'templates', 'ssi_include.html',
  12. )})
  13. def test_ssi01(self):
  14. output = self.engine.render_to_string('ssi01')
  15. self.assertEqual(output, 'This is for testing an ssi include. {{ test }}\n')
  16. @setup({'ssi02': '{%% ssi "%s" %%}' % os.path.join(
  17. ROOT, 'not_here',
  18. )})
  19. def test_ssi02(self):
  20. output = self.engine.render_to_string('ssi02')
  21. self.assertEqual(output, ''),
  22. @setup({'ssi03': "{%% ssi '%s' %%}" % os.path.join(
  23. ROOT, 'not_here',
  24. )})
  25. def test_ssi03(self):
  26. output = self.engine.render_to_string('ssi03')
  27. self.assertEqual(output, ''),
  28. # Test passing as a variable
  29. @setup({'ssi04': '{% ssi ssi_file %}'})
  30. def test_ssi04(self):
  31. output = self.engine.render_to_string('ssi04', {
  32. 'ssi_file': os.path.join(ROOT, 'templates', 'ssi_include.html')
  33. })
  34. self.assertEqual(output, 'This is for testing an ssi include. {{ test }}\n')
  35. @setup({'ssi05': '{% ssi ssi_file %}'})
  36. def test_ssi05(self):
  37. output = self.engine.render_to_string('ssi05', {'ssi_file': 'no_file'})
  38. self.assertEqual(output, '')
  39. # Test parsed output
  40. @setup({'ssi06': '{%% ssi "%s" parsed %%}' % os.path.join(
  41. ROOT, 'templates', 'ssi_include.html',
  42. )})
  43. def test_ssi06(self):
  44. output = self.engine.render_to_string('ssi06', {'test': 'Look ma! It parsed!'})
  45. self.assertEqual(output, 'This is for testing an ssi include. '
  46. 'Look ma! It parsed!\n')
  47. @setup({'ssi07': '{%% ssi "%s" parsed %%}' % os.path.join(
  48. ROOT, 'not_here',
  49. )})
  50. def test_ssi07(self):
  51. output = self.engine.render_to_string('ssi07', {'test': 'Look ma! It parsed!'})
  52. self.assertEqual(output, '')
  53. # Test space in file name
  54. @setup({'ssi08': '{%% ssi "%s" %%}' % os.path.join(
  55. ROOT, 'templates', 'ssi include with spaces.html',
  56. )})
  57. def test_ssi08(self):
  58. output = self.engine.render_to_string('ssi08')
  59. self.assertEqual(output, 'This is for testing an ssi include '
  60. 'with spaces in its name. {{ test }}\n')
  61. @setup({'ssi09': '{%% ssi "%s" parsed %%}' % os.path.join(
  62. ROOT, 'templates', 'ssi include with spaces.html',
  63. )})
  64. def test_ssi09(self):
  65. output = self.engine.render_to_string('ssi09', {'test': 'Look ma! It parsed!'})
  66. self.assertEqual(output, 'This is for testing an ssi include '
  67. 'with spaces in its name. Look ma! It parsed!\n')
  68. @ignore_warnings(category=RemovedInDjango110Warning)
  69. class SSISecurityTests(SimpleTestCase):
  70. def setUp(self):
  71. self.ssi_dir = os.path.join(ROOT, "templates", "first")
  72. self.engine = Engine(allowed_include_roots=(self.ssi_dir,))
  73. def render_ssi(self, path):
  74. # the path must exist for the test to be reliable
  75. self.assertTrue(os.path.exists(path))
  76. return self.engine.from_string('{%% ssi "%s" %%}' % path).render(Context({}))
  77. def test_allowed_paths(self):
  78. acceptable_path = os.path.join(self.ssi_dir, "..", "first", "test.html")
  79. self.assertEqual(self.render_ssi(acceptable_path), 'First template\n')
  80. def test_relative_include_exploit(self):
  81. """
  82. May not bypass allowed_include_roots with relative paths
  83. e.g. if allowed_include_roots = ("/var/www",), it should not be
  84. possible to do {% ssi "/var/www/../../etc/passwd" %}
  85. """
  86. disallowed_paths = [
  87. os.path.join(self.ssi_dir, "..", "ssi_include.html"),
  88. os.path.join(self.ssi_dir, "..", "second", "test.html"),
  89. ]
  90. for disallowed_path in disallowed_paths:
  91. self.assertEqual(self.render_ssi(disallowed_path), '')