Example #1
0
 def test_comment(self):
     data = '<!-- javascript:alert("Hello"); -->'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = ''
     self.assertEqual(data_return, expected)
Example #2
0
 def test_onmouseover(self):
     data = '<b onMouseOver="self.location.href=\'www.free.fr\'">Hello</b>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<b>Hello</b>'
     self.assertEqual(data_return, expected)
Example #3
0
 def test_links(self):
     data = '<a href="javascript:alert(\'Hello\')">Hello World</a>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<a>Hello World</a>'
     self.assertEqual(data_return, expected)
Example #4
0
 def test_javascript(self):
     data = '<div><script>alert("Hello world")</script></div>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<div></div>'
     self.assertEqual(data_return, expected)
Example #5
0
 def test_css(self):
     data = '<div style="background: url(javascript:void);"></div>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<div></div>'
     self.assertEqual(data_return, expected)
Example #6
0
 def test_comment(self):
     data = '<!-- javascript:alert("Hello"); -->'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = ''
     self.assertEqual(data_return, expected)
Example #7
0
 def test_links(self):
     data = '<a href="javascript:alert(\'Hello\')">Hello World</a>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<a>Hello World</a>'
     self.assertEqual(data_return, expected)
Example #8
0
 def test_onmouseover(self):
     data = '<b onMouseOver="self.location.href=\'www.free.fr\'">Hello</b>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<b>Hello</b>'
     self.assertEqual(data_return, expected)
Example #9
0
 def test_css(self):
     data = '<div style="background: url(javascript:void);"></div>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<div></div>'
     self.assertEqual(data_return, expected)
Example #10
0
 def test_javascript(self):
     data = '<div><script>alert("Hello world")</script></div>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<div></div>'
     self.assertEqual(data_return, expected)