spec/mspec/tool/wrap_with_guard.rb 'ruby_version_is ...3.5' spec/ruby/security/cve_2020_10663_spec.rb

This commit is contained in:
Hiroshi SHIBATA 2025-03-28 12:02:59 +09:00
parent 09b9468873
commit 2ba37d24e8
Notes: git 2025-03-28 03:45:10 +00:00

View File

@ -1,46 +1,49 @@
require_relative '../spec_helper' require_relative '../spec_helper'
require 'json'
module JSONSpecs ruby_version_is ""..."3.5" do
class MyClass require 'json'
def initialize(foo)
@foo = foo
end
def self.json_create(hash) module JSONSpecs
new(*hash['args']) class MyClass
end def initialize(foo)
@foo = foo
def to_json(*args)
{ 'json_class' => self.class.name, 'args' => [ @foo ] }.to_json(*args)
end
end
end
guard -> {
JSON.const_defined?(:Pure) or
version_is(JSON::VERSION, '2.3.0')
} do
describe "CVE-2020-10663 is resisted by" do
it "only creating custom objects if passed create_additions: true or using JSON.load" do
obj = JSONSpecs::MyClass.new("bar")
JSONSpecs::MyClass.should.json_creatable?
json = JSON.dump(obj)
JSON.parse(json, create_additions: true).class.should == JSONSpecs::MyClass
JSON(json, create_additions: true).class.should == JSONSpecs::MyClass
if version_is(JSON::VERSION, '2.8.0')
warning = /\Wcreate_additions:\s*true\W\s+is\s+deprecated/
else
warning = ''
end end
-> {
JSON.load(json).class.should == JSONSpecs::MyClass
}.should output_to_fd(warning, STDERR)
JSON.parse(json).class.should == Hash def self.json_create(hash)
JSON.parse(json, nil).class.should == Hash new(*hash['args'])
JSON(json).class.should == Hash end
def to_json(*args)
{ 'json_class' => self.class.name, 'args' => [ @foo ] }.to_json(*args)
end
end
end
guard -> {
JSON.const_defined?(:Pure) or
version_is(JSON::VERSION, '2.3.0')
} do
describe "CVE-2020-10663 is resisted by" do
it "only creating custom objects if passed create_additions: true or using JSON.load" do
obj = JSONSpecs::MyClass.new("bar")
JSONSpecs::MyClass.should.json_creatable?
json = JSON.dump(obj)
JSON.parse(json, create_additions: true).class.should == JSONSpecs::MyClass
JSON(json, create_additions: true).class.should == JSONSpecs::MyClass
if version_is(JSON::VERSION, '2.8.0')
warning = /\Wcreate_additions:\s*true\W\s+is\s+deprecated/
else
warning = ''
end
-> {
JSON.load(json).class.should == JSONSpecs::MyClass
}.should output_to_fd(warning, STDERR)
JSON.parse(json).class.should == Hash
JSON.parse(json, nil).class.should == Hash
JSON(json).class.should == Hash
end
end end
end end
end end