mirror of https://github.com/go-gitea/gitea.git
You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
39 lines
1.1 KiB
39 lines
1.1 KiB
// Copyright 2017 The Gitea Authors. All rights reserved. |
|
// SPDX-License-Identifier: MIT |
|
|
|
package integration |
|
|
|
import ( |
|
"net/http" |
|
"testing" |
|
|
|
"code.gitea.io/gitea/models/unittest" |
|
user_model "code.gitea.io/gitea/models/user" |
|
"code.gitea.io/gitea/tests" |
|
|
|
"github.com/stretchr/testify/assert" |
|
) |
|
|
|
func TestXSSUserFullName(t *testing.T) { |
|
defer tests.PrepareTestEnv(t)() |
|
user := unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: 2}) |
|
const fullName = `name & <script class="evil">alert('Oh no!');</script>` |
|
|
|
session := loginUser(t, user.Name) |
|
req := NewRequestWithValues(t, "POST", "/user/settings", map[string]string{ |
|
"_csrf": GetUserCSRFToken(t, session), |
|
"name": user.Name, |
|
"full_name": fullName, |
|
"email": user.Email, |
|
"language": "en-US", |
|
}) |
|
session.MakeRequest(t, req, http.StatusSeeOther) |
|
|
|
req = NewRequestf(t, "GET", "/%s", user.Name) |
|
resp := session.MakeRequest(t, req, http.StatusOK) |
|
htmlDoc := NewHTMLParser(t, resp.Body) |
|
assert.Equal(t, 0, htmlDoc.doc.Find("script.evil").Length()) |
|
assert.Equal(t, fullName, |
|
htmlDoc.doc.Find("div.content").Find(".header.text.center").Text(), |
|
) |
|
}
|
|
|