From 6434c9c4e1a126c2b660e218809a4afba4906904 Mon Sep 17 00:00:00 2001 From: mptyl Date: Mon, 3 Aug 2026 21:22:08 +0200 Subject: [PATCH] fix: reject reserved Git HEAD branch --- backend/src/config.ts | 1 + backend/test/workspaces-config.test.ts | 5 +++++ 2 files changed, 6 insertions(+) diff --git a/backend/src/config.ts b/backend/src/config.ts index a52df4b3..84b8e006 100644 --- a/backend/src/config.ts +++ b/backend/src/config.ts @@ -45,6 +45,7 @@ function refSafeGitBranch(value: string): string { const branch = requiredRegistryValue(value, "branch"); if ( branch === "@" + || branch === "HEAD" || branch.startsWith("-") || branch.startsWith("/") || branch.endsWith("/") diff --git a/backend/test/workspaces-config.test.ts b/backend/test/workspaces-config.test.ts index 10c14853..de1e7a0a 100644 --- a/backend/test/workspaces-config.test.ts +++ b/backend/test/workspaces-config.test.ts @@ -53,6 +53,11 @@ test("rejects ref-unsafe Git branches", () => { } }); +test("rejects the reserved HEAD branch without rejecting lowercase head", () => { + expect(() => loadConfig({ THT_WORKSPACE_GIT_BRANCH: "HEAD" })).toThrow(/branch/i); + expect(loadConfig({ THT_WORKSPACE_GIT_BRANCH: "head" }).workspaceRegistry.branch).toBe("head"); +}); + test("rejects control characters in installation IDs", () => { for (const codePoint of [...Array(0x20).keys(), ...Array(0x21).keys()].map((code, index) => ( index < 0x20 ? code : code + 0x7f