26 lines
770 B
JavaScript
26 lines
770 B
JavaScript
'use strict';
|
|
|
|
const assert = require('node:assert/strict');
|
|
const test = require('node:test');
|
|
|
|
const gitrepo = require('../src/lib/gitrepo');
|
|
const gitref = require('../src/lib/gitref');
|
|
|
|
test('assertSafeBranchRef 接受一般分支名稱', () => {
|
|
assert.equal(gitref.assertSafeBranchRef('feature/review-123', 'baseRef'), 'feature/review-123');
|
|
});
|
|
|
|
test('assertSafeBranchRef 拒絕路徑穿越分支名稱', () => {
|
|
assert.throws(
|
|
() => gitref.assertSafeBranchRef('../../hooks/pre-push', 'baseRef'),
|
|
/不是安全的分支名稱/,
|
|
);
|
|
});
|
|
|
|
test('resolveMergeBase 會在 git fetch 前拒絕不安全 baseRef', () => {
|
|
assert.throws(
|
|
() => gitrepo.resolveMergeBase(process.cwd(), '../../hooks/pre-push'),
|
|
/不是安全的分支名稱/,
|
|
);
|
|
});
|