From 2e130fb0c611fb223326ee0c84751fbdeacc9946 Mon Sep 17 00:00:00 2001 From: Martin Edenhofer Date: Tue, 14 Mar 2017 12:10:40 +0100 Subject: [PATCH] Improved html sanitizer with a tags without href attributes. --- test/unit/html_sanitizer_test.rb | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/test/unit/html_sanitizer_test.rb b/test/unit/html_sanitizer_test.rb index b3cd39b7e..de6d0caff 100644 --- a/test/unit/html_sanitizer_test.rb +++ b/test/unit/html_sanitizer_test.rb @@ -62,7 +62,7 @@ tt p://6 6.000146.0x7.147/">XSS', true), 'http://66.000146.0x7.147/ ('), 'X') assert_equal(HtmlSanitizer.strict('CLICKME'), 'CLICKME') assert_equal(HtmlSanitizer.strict('CLICKME'), 'CLICKME') - assert_equal(HtmlSanitizer.strict('CLICKME', true), ' (CLICKME)') + assert_equal(HtmlSanitizer.strict('CLICKME', true), 'CLICKME') assert_equal(HtmlSanitizer.strict(''), '') assert_equal(HtmlSanitizer.strict(''), '') assert_equal(HtmlSanitizer.strict('><image xlink:href="'), '') @@ -71,7 +71,7 @@ tt p://6 6.000146.0x7.147/">XSS', true), 'http://66.000146.0x7.147/ ('), '') assert_equal(HtmlSanitizer.strict(''), '') assert_equal(HtmlSanitizer.strict('XXX'), 'XXX') - assert_equal(HtmlSanitizer.strict('XXX', true), ' (XXX)') + assert_equal(HtmlSanitizer.strict('XXX', true), 'XXX') assert_equal(HtmlSanitizer.strict(''), 'alert(1)') assert_equal(HtmlSanitizer.strict(''), '') assert_equal(HtmlSanitizer.strict('', true), 'http://example.com ()')