spec/mspec/tool/wrap_with_guard.rb 'ruby_version_is ...3.5' spec/ruby/security/cve_2020_10663_spec.rb
This commit is contained in:
parent
09b9468873
commit
2ba37d24e8
Notes:
git
2025-03-28 03:45:10 +00:00
@ -1,46 +1,49 @@
|
|||||||
require_relative '../spec_helper'
|
require_relative '../spec_helper'
|
||||||
require 'json'
|
|
||||||
|
|
||||||
module JSONSpecs
|
ruby_version_is ""..."3.5" do
|
||||||
class MyClass
|
require 'json'
|
||||||
def initialize(foo)
|
|
||||||
@foo = foo
|
|
||||||
end
|
|
||||||
|
|
||||||
def self.json_create(hash)
|
module JSONSpecs
|
||||||
new(*hash['args'])
|
class MyClass
|
||||||
end
|
def initialize(foo)
|
||||||
|
@foo = foo
|
||||||
def to_json(*args)
|
|
||||||
{ 'json_class' => self.class.name, 'args' => [ @foo ] }.to_json(*args)
|
|
||||||
end
|
|
||||||
end
|
|
||||||
end
|
|
||||||
|
|
||||||
guard -> {
|
|
||||||
JSON.const_defined?(:Pure) or
|
|
||||||
version_is(JSON::VERSION, '2.3.0')
|
|
||||||
} do
|
|
||||||
describe "CVE-2020-10663 is resisted by" do
|
|
||||||
it "only creating custom objects if passed create_additions: true or using JSON.load" do
|
|
||||||
obj = JSONSpecs::MyClass.new("bar")
|
|
||||||
JSONSpecs::MyClass.should.json_creatable?
|
|
||||||
json = JSON.dump(obj)
|
|
||||||
|
|
||||||
JSON.parse(json, create_additions: true).class.should == JSONSpecs::MyClass
|
|
||||||
JSON(json, create_additions: true).class.should == JSONSpecs::MyClass
|
|
||||||
if version_is(JSON::VERSION, '2.8.0')
|
|
||||||
warning = /\Wcreate_additions:\s*true\W\s+is\s+deprecated/
|
|
||||||
else
|
|
||||||
warning = ''
|
|
||||||
end
|
end
|
||||||
-> {
|
|
||||||
JSON.load(json).class.should == JSONSpecs::MyClass
|
|
||||||
}.should output_to_fd(warning, STDERR)
|
|
||||||
|
|
||||||
JSON.parse(json).class.should == Hash
|
def self.json_create(hash)
|
||||||
JSON.parse(json, nil).class.should == Hash
|
new(*hash['args'])
|
||||||
JSON(json).class.should == Hash
|
end
|
||||||
|
|
||||||
|
def to_json(*args)
|
||||||
|
{ 'json_class' => self.class.name, 'args' => [ @foo ] }.to_json(*args)
|
||||||
|
end
|
||||||
|
end
|
||||||
|
end
|
||||||
|
|
||||||
|
guard -> {
|
||||||
|
JSON.const_defined?(:Pure) or
|
||||||
|
version_is(JSON::VERSION, '2.3.0')
|
||||||
|
} do
|
||||||
|
describe "CVE-2020-10663 is resisted by" do
|
||||||
|
it "only creating custom objects if passed create_additions: true or using JSON.load" do
|
||||||
|
obj = JSONSpecs::MyClass.new("bar")
|
||||||
|
JSONSpecs::MyClass.should.json_creatable?
|
||||||
|
json = JSON.dump(obj)
|
||||||
|
|
||||||
|
JSON.parse(json, create_additions: true).class.should == JSONSpecs::MyClass
|
||||||
|
JSON(json, create_additions: true).class.should == JSONSpecs::MyClass
|
||||||
|
if version_is(JSON::VERSION, '2.8.0')
|
||||||
|
warning = /\Wcreate_additions:\s*true\W\s+is\s+deprecated/
|
||||||
|
else
|
||||||
|
warning = ''
|
||||||
|
end
|
||||||
|
-> {
|
||||||
|
JSON.load(json).class.should == JSONSpecs::MyClass
|
||||||
|
}.should output_to_fd(warning, STDERR)
|
||||||
|
|
||||||
|
JSON.parse(json).class.should == Hash
|
||||||
|
JSON.parse(json, nil).class.should == Hash
|
||||||
|
JSON(json).class.should == Hash
|
||||||
|
end
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
Loading…
x
Reference in New Issue
Block a user