Keep an unrecognised status inside its code span
`status_phrase` renders a status it does not know verbatim, deliberately:
`argparse`'s `choices=` would exit 2 on an unexpected value and the log --
the entire reason this script exists -- would never be posted.
But the verbatim value lands in a code span inside a **bold** header, so a
backtick in it closes the span early and the rest renders as markdown:
--status 'x` **loud** `y'
-> **`tests` finished with status `x` **loud** `y`**
Nothing hostile is expected: the value comes from `${{ job.status }}` or a
hand-written flag, both written by whoever wrote the workflow. It is worth
closing anyway because this repo is public and four others consume the
script as a composite action, so a branch name or a matrix value could
reach this argument later without anyone revisiting this function.
Backticks are removed rather than escaped -- there is no escape for a
backtick inside a code span, only a wider fence, and the status is a short
word rather than something whose exact bytes matter.
Found in the cold re-read of #10, not by the suite, so the test that
covers it was proved to fail without the fix.
Co-authored-by: bit <bit@das-labor.org>
This commit is contained in:
@@ -313,6 +313,15 @@ class TestStatusPhrase(unittest.TestCase):
|
||||
self.assertEqual(report_job_log.status_phrase("weird"),
|
||||
"finished with status `weird`")
|
||||
|
||||
def test_a_backtick_in_an_unknown_status_cannot_escape_the_code_span(self):
|
||||
"""The verbatim value sits in a code span inside a **bold** header, so
|
||||
a backtick in it would close the span and let the rest render as
|
||||
markdown. `${{ job.status }}` is workflow-author-controlled rather than
|
||||
hostile, but this script is public and shared by four repos."""
|
||||
phrase = report_job_log.status_phrase("x` **loud** `y")
|
||||
self.assertEqual(phrase, "finished with status `x **loud** y`")
|
||||
self.assertEqual(phrase.count("`"), 2)
|
||||
|
||||
def test_default_constant_is_failed(self):
|
||||
"""Named so that changing it is a deliberate act, not a typo."""
|
||||
self.assertEqual(report_job_log.DEFAULT_STATUS, "failed")
|
||||
|
||||
Reference in New Issue
Block a user