sync/tests/xss.js

22 lines
709 B
JavaScript

var sanitize = require('../lib/xss').sanitizeHTML;
var assert = require('assert');
function basicTest() {
assert(sanitize("< script src = bad.js>blah</script>") ===
"[tag removed]blah[tag removed]");
assert(sanitize("< img src=asdf onerror='alert(\"xss\")'>") ===
"<img src=\"asdf\">");
assert(sanitize("<a href='javascript:alert(document.cookie)'>") ===
"<a href=\"[removed]:[removed]([removed])\">");
assert(sanitize("<a ") === "<a>");
assert(sanitize("<img src=\"<a href=\"javascript:void(0)\">>") ===
"<img src=\"<a href=\" javascriptvoid0=\"\">>");
}
basicTest();
console.log("Tests passed.");