Exemplo n.º 1
0
 def test_comment(self):
     data = '<!-- javascript:alert("Hello"); -->'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = ''
     self.assertEqual(data_return, expected)
Exemplo n.º 2
0
 def test_onmouseover(self):
     data = '<b onMouseOver="self.location.href=\'www.free.fr\'">Hello</b>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<b>Hello</b>'
     self.assertEqual(data_return, expected)
Exemplo n.º 3
0
 def test_links(self):
     data = '<a href="javascript:alert(\'Hello\')">Hello World</a>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<a>Hello World</a>'
     self.assertEqual(data_return, expected)
Exemplo n.º 4
0
 def test_javascript(self):
     data = '<div><script>alert("Hello world")</script></div>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<div></div>'
     self.assertEqual(data_return, expected)
Exemplo n.º 5
0
 def test_css(self):
     data = '<div style="background: url(javascript:void);"></div>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<div></div>'
     self.assertEqual(data_return, expected)
Exemplo n.º 6
0
 def test_comment(self):
     data = '<!-- javascript:alert("Hello"); -->'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = ''
     self.assertEqual(data_return, expected)
Exemplo n.º 7
0
 def test_links(self):
     data = '<a href="javascript:alert(\'Hello\')">Hello World</a>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<a>Hello World</a>'
     self.assertEqual(data_return, expected)
Exemplo n.º 8
0
 def test_onmouseover(self):
     data = '<b onMouseOver="self.location.href=\'www.free.fr\'">Hello</b>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<b>Hello</b>'
     self.assertEqual(data_return, expected)
Exemplo n.º 9
0
 def test_css(self):
     data = '<div style="background: url(javascript:void);"></div>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<div></div>'
     self.assertEqual(data_return, expected)
Exemplo n.º 10
0
 def test_javascript(self):
     data = '<div><script>alert("Hello world")</script></div>'
     stream = sanitize_str(data)
     data_return = stream_to_html(stream)
     expected = '<div></div>'
     self.assertEqual(data_return, expected)