sync/tests/xss.js

47 lines
1.7 KiB
JavaScript
Raw Normal View History

2013-11-05 16:37:50 +00:00
var sanitize = require('../lib/xss');
var sanitizeHTML = sanitize.sanitizeHTML;
var sanitizeText = sanitize.sanitizeText;
var decodeText = sanitize.decodeText;
2013-10-31 05:39:35 +00:00
var assert = require('assert');
2013-11-05 16:37:50 +00:00
var failed = 0;
2013-10-31 05:39:35 +00:00
2013-11-05 16:37:50 +00:00
function doTest(s, src, expected) {
try {
assert(s(src) === expected);
} catch (e) {
failed++;
console.log("Expected '" + expected + "'");
console.log("Got '" + s(src) + "'");
}
}
function testSanitizeHTML() {
doTest(sanitizeHTML, "< script src = bad.js>blah</script>", "[tag removed]blah[tag removed]");
doTest(sanitizeHTML, "< img src=asdf onerror='alert(\"xss\")'>", "<img src=\"asdf\">");
2013-10-31 05:39:35 +00:00
2013-11-05 16:37:50 +00:00
doTest(sanitizeHTML, "<a href='javascript:alert(document.cookie)'>", "<a href=\"[removed]:[removed]([removed])\">");
2013-10-31 05:39:35 +00:00
2013-11-05 16:37:50 +00:00
doTest(sanitizeHTML, "<a ", "<a>");
2013-10-31 05:48:01 +00:00
2013-11-05 16:37:50 +00:00
doTest(sanitizeHTML, "<img src=\"<a href=\"javascript:void(0)\">>", "<img src=\"<a href=\" javascriptvoid0>>");
}
function testSanitizeText() {
doTest(sanitizeText, "<a href=\"#\" onerror=\"javascript:alert('xss')\">", "&lt;a href=&quot;#&quot; onerror=&quot;javascript:alert&#40;&#39;xss&#39;&#41;&quot;&gt;");
doTest(sanitizeText, "&lt;&gt;&amp;&quot;&ccedil;&#x09", "&amp;lt;&amp;gt;&amp;amp;&amp;quot;&amp;ccedil;&amp;#x09");
}
2013-10-31 05:48:01 +00:00
2013-11-05 16:37:50 +00:00
function testDecode() {
doTest(decodeText, "&lt;a href=&quot;#&quot; onerror=&quot;javascript:alert&#40;&#39;xss&#39;&#41;&quot;&gt;", "<a href=\"#\" onerror=\"javascript:alert('xss')\">");
doTest(decodeText, "&amp;lt;&amp;gt;&amp;amp;&amp;quot;&amp;ccedil;&amp;#x09", "&lt;&gt;&amp;&quot;&ccedil;&#x09");
2013-10-31 05:39:35 +00:00
}
2013-11-05 16:37:50 +00:00
testSanitizeHTML();
testSanitizeText();
testDecode();
if (!failed)
console.log("Tests passed.");
else
console.log(""+failed, "tests failed");