forked from Wavyzz/dolibarr
More complete phpunit
This commit is contained in:
@@ -177,6 +177,7 @@ class SecurityTest extends PHPUnit\Framework\TestCase
|
||||
$_GET["param4"]='../dir';
|
||||
$_GET["param5"]="a_1-b";
|
||||
$_POST["param6"]=""><svg onload='console.log("Stored XSS ")'>";
|
||||
$_GET["param7"]='"c:\this is a path~1\aaa" abc<bad>def</bad>';
|
||||
|
||||
// Test int
|
||||
$result=GETPOST('id', 'int'); // Must return nothing
|
||||
@@ -229,6 +230,10 @@ class SecurityTest extends PHPUnit\Framework\TestCase
|
||||
print __METHOD__." result=".$result."\n";
|
||||
$this->assertEquals('">', $result);
|
||||
|
||||
$result=GETPOST("param7", 'restricthtml');
|
||||
print __METHOD__." result=".$result."\n";
|
||||
$this->assertEquals('"c:\this is a path~1\aaa" abcdef', $result);
|
||||
|
||||
return $result;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user