diff --git a/conservancy/tests.py b/conservancy/tests.py index 7ef3eed2c71c846ad60add7437dc867f33ebbd3d..e81ad13b2db9db85f793cd970871f35863c31be7 100644 --- a/conservancy/tests.py +++ b/conservancy/tests.py @@ -1,5 +1,6 @@ import datetime +from django.conf import settings from django.http import Http404 import pytest from pytest_django.asserts import assertContains, assertTemplateUsed @@ -35,6 +36,7 @@ def test_annual_report_file_served(rf): def test_path_traversal_404s(rf): + assert (settings.BASE_DIR / 'static' / 'about/../../settings.py').exists() request = rf.get('/about/../../settings.py') with pytest.raises(Http404): views.index(request)