Sha256: 69cbf5671594e6c39179fe804045e7a84de31da6419cb47e4d1510b81f863a55

Contents?: true

Size: 1.65 KB

Versions: 14

Compression:

Stored size: 1.65 KB

Contents

# encoding: utf-8
require_relative 'common'

describe 'Sanitize::Transformers::CSS::CleanAttribute' do
  make_my_diffs_pretty!
  parallelize_me!

  before do
    @s = Sanitize.new(Sanitize::Config::RELAXED)
  end

  it 'should sanitize CSS properties in style attributes' do
    @s.fragment(%[
      <div style="color: #fff; width: expression(alert(1)); /* <-- evil! */"></div>
    ].strip).must_equal %[
      <div style="color: #fff;  /* &lt;-- evil! */"></div>
    ].strip
  end

  it 'should remove the style attribute if the sanitized CSS is empty' do
    @s.fragment('<div style="width: expression(alert(1))"></div>').
      must_equal '<div></div>'
  end
end

describe 'Sanitize::Transformers::CSS::CleanElement' do
  make_my_diffs_pretty!
  parallelize_me!

  before do
    @s = Sanitize.new(Sanitize::Config::RELAXED)
  end

  it 'should sanitize CSS stylesheets in <style> elements' do
    html = %[
      <style>@import url(evil.css);
      /* Yay CSS! */
      .foo { color: #fff; }
      #bar { background: url(yay.jpg); bogus: wtf; }
      .evil { width: expression(xss()); }

      @media screen (max-width:480px) {
        .foo { width: 400px; }
        #bar:not(.baz) { height: 100px; }
      }
      </style>
    ].strip

    @s.fragment(html).must_equal %[
      <style>
      /* Yay CSS! */
      .foo { color: #fff; }
      #bar { background: url(yay.jpg);  }
      .evil {  }

      @media screen (max-width:480px) {
        .foo { width: 400px; }
        #bar:not(.baz) { height: 100px; }
      }
      </style>
    ].strip
  end

  it 'should remove the <style> element if the sanitized CSS is empty' do
    @s.fragment('<style></style>').must_equal ''
  end
end

Version data entries

14 entries across 14 versions & 1 rubygems

Version Path
sanitize-4.6.6 test/test_clean_css.rb
sanitize-4.6.5 test/test_clean_css.rb
sanitize-4.6.4 test/test_clean_css.rb
sanitize-4.6.3 test/test_clean_css.rb
sanitize-4.6.2 test/test_clean_css.rb
sanitize-4.6.1 test/test_clean_css.rb
sanitize-4.6.0 test/test_clean_css.rb
sanitize-4.5.0 test/test_clean_css.rb
sanitize-4.4.0 test/test_clean_css.rb
sanitize-4.3.0 test/test_clean_css.rb
sanitize-4.2.0 test/test_clean_css.rb
sanitize-4.1.0 test/test_clean_css.rb
sanitize-4.0.1 test/test_clean_css.rb
sanitize-4.0.0 test/test_clean_css.rb