Files
sdk/tests/lib_2/html/trusted_html_tree_sanitizer_test.dart
T
Jakob Roland Andersen 0955c0ca9e Migrated test batch 211 to Dart 2.0.
Bug:
Change-Id: Iee8198332fd94ef708eab1aa34867c5d68054c6a
Reviewed-on: https://dart-review.googlesource.com/10420
Commit-Queue: Jakob Roland Andersen <jakobr@google.com>
Reviewed-by: Florian Loitsch <floitsch@google.com>
2017-10-04 21:27:40 +00:00

62 lines
1.9 KiB
Dart

// Copyright (c) 2013, the Dart project authors. Please see the AUTHORS file
// for details. All rights reserved. Use of this source code is governed by a
// BSD-style license that can be found in the LICENSE file.
/// This tests HTML validation and sanitization, which is very important
/// for prevent XSS or other attacks. If you suppress this, or parts of it
/// please make it a critical bug and bring it to the attention of the
/// dart:html maintainers.
import 'dart:js' as js;
import 'dart:html';
import 'dart:svg' as svg;
import 'package:expect/minitest.dart';
import 'utils.dart';
var oldAdoptNode;
var jsDocument;
/// We want to verify that with the trusted sanitizer we are not
/// creating a document fragment. So make DocumentFragment operation
/// throw.
makeDocumentFragmentAdoptionThrow() {
var document = js.context['document'];
jsDocument = new js.JsObject.fromBrowserObject(document);
oldAdoptNode = jsDocument['adoptNode'];
jsDocument['adoptNode'] = null;
}
restoreOldAdoptNode() {
jsDocument['adoptNode'] = oldAdoptNode;
}
main() {
group('not_create_document_fragment', () {
setUp(makeDocumentFragmentAdoptionThrow);
tearDown(restoreOldAdoptNode);
test('setInnerHtml', () {
document.body.setInnerHtml('<div foo="baz">something</div>',
treeSanitizer: NodeTreeSanitizer.trusted);
expect(document.body.innerHtml, '<div foo="baz">something</div>');
});
test("appendHtml", () {
var oldStuff = document.body.innerHtml;
var newStuff = '<div rumplestiltskin="value">content</div>';
document.body
.appendHtml(newStuff, treeSanitizer: NodeTreeSanitizer.trusted);
expect(document.body.innerHtml, oldStuff + newStuff);
});
});
group('untrusted', () {
setUp(makeDocumentFragmentAdoptionThrow);
tearDown(restoreOldAdoptNode);
test('untrusted', () {
expect(() => document.body.innerHtml = "<p>anything</p>", throws);
});
});
}