diff contrib/dumprevlog @ 36752:bbd4027b019b stable

tests: comprehensively test HTTP server permissions checking We didn't have test coverage for numerous web.* config options. We add that test coverage. Included in the tests are tests for custom commands. We have commands that are supposedly read-only and perform writes and a variation of each that does and does not define its operation type in hgweb_mod.perms. The tests reveal a handful of security bugs related to permissions checking. Subsequent commits will address these security bugs.
author Gregory Szorc <gregory.szorc@gmail.com>
date Tue, 20 Feb 2018 19:09:01 -0800
parents 6359b80f15fb
children a915465a731e
line wrap: on
line diff