mirror of
https://github.com/inventree/InvenTree.git
synced 2025-05-03 22:08:49 +00:00
Adds a simple unit test to ensure that bleach is running on API data (#3222)
This commit is contained in:
parent
9ba3fdf23d
commit
eeff6074e7
@ -148,6 +148,37 @@ class PartCategoryAPITest(InvenTreeAPITestCase):
|
|||||||
# There should not be any templates left at this point
|
# There should not be any templates left at this point
|
||||||
self.assertEqual(PartCategoryParameterTemplate.objects.count(), 0)
|
self.assertEqual(PartCategoryParameterTemplate.objects.count(), 0)
|
||||||
|
|
||||||
|
def test_bleach(self):
|
||||||
|
"""Test that the data cleaning functionality is working"""
|
||||||
|
|
||||||
|
url = reverse('api-part-category-detail', kwargs={'pk': 1})
|
||||||
|
|
||||||
|
self.patch(
|
||||||
|
url,
|
||||||
|
{
|
||||||
|
'description': '<img src=# onerror=alert("pwned")>',
|
||||||
|
},
|
||||||
|
expected_code=200
|
||||||
|
)
|
||||||
|
|
||||||
|
cat = PartCategory.objects.get(pk=1)
|
||||||
|
|
||||||
|
# Image tags have been stripped
|
||||||
|
self.assertEqual(cat.description, '<img src=# onerror=alert("pwned")>')
|
||||||
|
|
||||||
|
self.patch(
|
||||||
|
url,
|
||||||
|
{
|
||||||
|
'description': '<a href="www.google.com">LINK</a><script>alert("h4x0r")</script>',
|
||||||
|
},
|
||||||
|
expected_code=200,
|
||||||
|
)
|
||||||
|
|
||||||
|
# Tags must have been bleached out
|
||||||
|
cat.refresh_from_db()
|
||||||
|
|
||||||
|
self.assertEqual(cat.description, '<a href="www.google.com">LINK</a><script>alert("h4x0r")</script>')
|
||||||
|
|
||||||
|
|
||||||
class PartOptionsAPITest(InvenTreeAPITestCase):
|
class PartOptionsAPITest(InvenTreeAPITestCase):
|
||||||
"""Tests for the various OPTIONS endpoints in the /part/ API.
|
"""Tests for the various OPTIONS endpoints in the /part/ API.
|
||||||
|
Loading…
x
Reference in New Issue
Block a user