mirror of
https://github.com/naturalcrit/homebrewery.git
synced 2026-01-07 14:12:43 +00:00
Update HTML test
This commit is contained in:
@@ -16,10 +16,10 @@ test('Javascript via src', function() {
|
|||||||
expect(rendered).toBe('<img>');
|
expect(rendered).toBe('<img>');
|
||||||
});
|
});
|
||||||
|
|
||||||
test('Javascript via action', function() {
|
test('Javascript via form submit action', function() {
|
||||||
const source = `<form action="javascript:alert('This is a JavaScript injection via action attribute')">\n<input type="submit" value="Submit">\n</form>`;
|
const source = `<form action="javascript:alert('This is a JavaScript injection via action attribute')">\n<input type="submit" value="Submit">\n</form>`;
|
||||||
const rendered = safeHTML(source);
|
const rendered = safeHTML(source);
|
||||||
expect(rendered).toBe('<form>\n<input type=\"submit\" value=\"Submit\">\n</form>');
|
expect(rendered).toBe('<form>\n<input value=\"Submit\">\n</form>');
|
||||||
});
|
});
|
||||||
|
|
||||||
test('Javascript via inline event handler - onClick', function() {
|
test('Javascript via inline event handler - onClick', function() {
|
||||||
|
|||||||
Reference in New Issue
Block a user