diff --git a/conservancy/tests.py b/conservancy/tests.py index 7ef3eed2..e81ad13b 100644 --- a/conservancy/tests.py +++ b/conservancy/tests.py @@ -1,5 +1,6 @@ import datetime +from django.conf import settings from django.http import Http404 import pytest from pytest_django.asserts import assertContains, assertTemplateUsed @@ -35,6 +36,7 @@ def test_annual_report_file_served(rf): def test_path_traversal_404s(rf): + assert (settings.BASE_DIR / 'static' / 'about/../../settings.py').exists() request = rf.get('/about/../../settings.py') with pytest.raises(Http404): views.index(request)