def test_comment(self): data = '<!-- javascript:alert("Hello"); -->' stream = sanitize_str(data) data_return = stream_to_html(stream) expected = '' self.assertEqual(data_return, expected)
def test_onmouseover(self): data = '<b onMouseOver="self.location.href=\'www.free.fr\'">Hello</b>' stream = sanitize_str(data) data_return = stream_to_html(stream) expected = '<b>Hello</b>' self.assertEqual(data_return, expected)
def test_links(self): data = '<a href="javascript:alert(\'Hello\')">Hello World</a>' stream = sanitize_str(data) data_return = stream_to_html(stream) expected = '<a>Hello World</a>' self.assertEqual(data_return, expected)
def test_javascript(self): data = '<div><script>alert("Hello world")</script></div>' stream = sanitize_str(data) data_return = stream_to_html(stream) expected = '<div></div>' self.assertEqual(data_return, expected)
def test_css(self): data = '<div style="background: url(javascript:void);"></div>' stream = sanitize_str(data) data_return = stream_to_html(stream) expected = '<div></div>' self.assertEqual(data_return, expected)