mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix: sanitize app status summary (#19075)
Fixes https://github.com/coder/coder/issues/18875
This commit is contained in:
@@ -3,6 +3,7 @@ package strings_test
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
|
||||
"github.com/coder/coder/v2/coderd/util/strings"
|
||||
@@ -37,3 +38,41 @@ func TestTruncate(t *testing.T) {
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestUISanitize(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
for _, tt := range []struct {
|
||||
s string
|
||||
expected string
|
||||
}{
|
||||
{"normal text", "normal text"},
|
||||
{"\tfoo \r\\nbar ", "foo bar"},
|
||||
{"通常のテキスト", "通常のテキスト"},
|
||||
{"foo\nbar", "foo bar"},
|
||||
{"foo\tbar", "foo bar"},
|
||||
{"foo\rbar", "foo bar"},
|
||||
{"foo\x00bar", "foobar"},
|
||||
{"\u202Eabc", "abc"},
|
||||
{"\u200Bzero width", "zero width"},
|
||||
{"foo\x1b[31mred\x1b[0mbar", "fooredbar"},
|
||||
{"foo\u0008bar", "foobar"},
|
||||
{"foo\x07bar", "foobar"},
|
||||
{"foo\uFEFFbar", "foobar"},
|
||||
{"<a href='javascript:alert(1)'>link</a>", "link"},
|
||||
{"<style>body{display:none}</style>", ""},
|
||||
{"<html>HTML</html>", "HTML"},
|
||||
{"<br>line break", "line break"},
|
||||
{"<link rel='stylesheet' href='evil.css'>", ""},
|
||||
{"<img src=1 onerror=alert(1)>", ""},
|
||||
{"<!-- comment -->visible", "visible"},
|
||||
{"<script>alert('xss')</script>", ""},
|
||||
{"<iframe src='evil.com'></iframe>", ""},
|
||||
} {
|
||||
t.Run(tt.expected, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
actual := strings.UISanitize(tt.s)
|
||||
assert.Equal(t, tt.expected, actual)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user