Files
Gitea/modules/gitrepo/hooks_test.go
T
Giteabot bf7b6f8bd4 fix(git): restrict hook permissions (#39008) (#39016)
Backport #39008 by @bircni

Create delegate hook files and directories without group or other write
access, including correcting existing hook directories.

_Assisted-by: Codex:GPT-5_

---------

Co-authored-by: bircni <bircni@icloud.com>
Co-authored-by: silverwind <me@silverwind.io>
2026-08-21 12:40:30 +00:00

35 lines
876 B
Go

// Copyright 2026 The Gitea Authors. All rights reserved.
// SPDX-License-Identifier: MIT
package gitrepo
import (
"os"
"path/filepath"
"testing"
"github.com/stretchr/testify/require"
)
func TestCreateDelegateHooksPermissions(t *testing.T) {
hookDir := t.TempDir()
existingHookDir := filepath.Join(hookDir, "post-receive.d")
require.NoError(t, os.MkdirAll(existingHookDir, 0o777))
require.NoError(t, os.Chmod(existingHookDir, 0o777))
require.NoError(t, createDelegateHooks(hookDir))
hookNames, _, _ := getHookTemplates()
for _, hookName := range hookNames {
for _, path := range []string{
filepath.Join(hookDir, hookName),
filepath.Join(hookDir, hookName+".d"),
filepath.Join(hookDir, hookName+".d", "gitea"),
} {
info, err := os.Stat(path)
require.NoError(t, err)
require.Equal(t, os.FileMode(0o755), info.Mode().Perm(), path)
}
}
}