51 lines
2.5 KiB
C#
51 lines
2.5 KiB
C#
using PrivaPub.Federation.Objects;
|
|||
|
|
|
||
|
|
namespace PrivaPub.Tests.Federation
|
||
|
|
{
|
||
|
|
public class ContentSanitizerTests
|
||
|
|
{
|
||
|
|
[Theory]
|
||
|
|
[InlineData("<script>alert(1)</script><p>hi</p>", "<p>hi</p>")]
|
||
|
|
[InlineData("<p onclick=\"alert(1)\">hi</p>", "<p>hi</p>")]
|
||
|
|
[InlineData("<img src=x onerror=alert(1)>", "")]
|
||
|
|
[InlineData("<a href=\"javascript:alert(1)\">x</a>", "<a rel=\"nofollow noopener noreferrer\" target=\"_blank\">x</a>")]
|
||
|
|
[InlineData("<a href=\"data:text/html,<script>alert(1)</script>\">x</a>", "<a rel=\"nofollow noopener noreferrer\" target=\"_blank\">x</a>")]
|
||
|
|
[InlineData("<a href=\"/relative\">x</a>", "<a rel=\"nofollow noopener noreferrer\" target=\"_blank\">x</a>")]
|
||
|
|
[InlineData("<iframe src=\"https://evil.example\"></iframe>text", "text")]
|
||
|
|
[InlineData("<style>body{display:none}</style><p>x</p>", "<p>x</p>")]
|
||
|
|
[InlineData("<svg><script>alert(1)</script></svg>", "")]
|
||
|
|
[InlineData("<p style=\"position:fixed\">x</p>", "<p>x</p>")]
|
||
|
|
[InlineData("<form action=\"https://evil.example\"><input name=p></form>ok", "ok")]
|
||
|
|
[InlineData("<p>a<!-- comment -->b</p>", "<p>ab</p>")]
|
||
|
|
[InlineData("<div><p>kept</p></div>", "<p>kept</p>")]
|
||
|
|
[InlineData("<h2>Title</h2>", "<p><strong>Title</strong></p>")]
|
||
|
|
[InlineData("<span class=\"evil big\">x</span>", "<span>x</span>")]
|
||
|
|
public void Removes_what_is_not_allowed(string input, string expected) =>
|
||
|
|
Assert.Equal(expected, ContentSanitizer.Html(input));
|
||
|
|
|
||
|
|
[Fact]
|
||
|
|
public void Keeps_mastodon_mention_and_hashtag_markup()
|
||
|
|
{
|
||
|
|
var html = "<p><span class=\"h-card\" translate=\"no\"><a href=\"https://m.example/@alice\" class=\"u-url mention\">@<span>alice</span></a></span> "
|
||
|
|
+ "<a href=\"https://m.example/tags/fedi\" class=\"mention hashtag\" rel=\"tag\">#<span>fedi</span></a> "
|
||
|
|
+ "<a href=\"https://example.org/a-long-link\"><span class=\"invisible\">https://</span><span class=\"ellipsis\">example.org/a-long</span></a></p>";
|
||
|
|
|
||
|
|
var sanitized = ContentSanitizer.Html(html);
|
||
|
|
|
||
|
|
Assert.Contains("class=\"h-card\"", sanitized);
|
||
|
|
Assert.Contains("class=\"u-url mention\"", sanitized);
|
||
|
|
Assert.Contains("class=\"mention hashtag\"", sanitized);
|
||
|
|
Assert.Contains("class=\"invisible\"", sanitized);
|
||
|
|
Assert.Contains("class=\"ellipsis\"", sanitized);
|
||
|
|
Assert.Contains("href=\"https://m.example/@alice\"", sanitized);
|
||
|
|
Assert.DoesNotContain("rel=\"tag\"", sanitized);
|
||
|
|
}
|
||
|
|
|
||
|
|
[Theory]
|
||
|
|
[InlineData("")]
|
||
|
|
[InlineData(" ")]
|
||
|
|
[InlineData(null)]
|
||
|
|
public void Empty_input_is_empty(string input) =>
|
||
|
|
Assert.Equal(string.Empty, ContentSanitizer.Html(input));
|
||
|
|
}
|
||
|
|
}
|