File tree Expand file tree Collapse file tree 2 files changed +5
-3
lines changed
Expand file tree Collapse file tree 2 files changed +5
-3
lines changed Original file line number Diff line number Diff line change @@ -723,7 +723,8 @@ export default [
723723 "expected" : [
724724 "<div id=\"134\">\n<img alt=\"%></xmp><img src=xx onerror=alert(134)//\">\n\n %>/\nalert(2)\n\n\nXXX\n<style>\n*['<!--']{}\n</style>\n-->{}\n*{color:red}//[\"'`-->]]>]</div>" ,
725725 "<div id=\"134\">\n<img alt=\"%></xmp><img src=xx onerror=alert(134)//\">\n\n %>/\nalert(2)\n\n\nXXX\n<style>\n*['<!--']{}\n</style>\n->{}\n*{color:red}//[\"'`-->]]>]</div>" ,
726- "<div id=\"134\">\n<img alt=\"%></xmp><img src=xx onerror=alert(134)//\">\n\n %>/\nalert(2)\n\n\nXXX\n\n-->{}\n*{color:red}//[\"'`-->]]>]</div>"
726+ "<div id=\"134\">\n<img alt=\"%></xmp><img src=xx onerror=alert(134)//\">\n\n %>/\nalert(2)\n\n\nXXX\n\n-->{}\n*{color:red}//[\"'`-->]]>]</div>" ,
727+ "<div id=\"134\">\n<img alt=\"%></xmp><img src=xx onerror=alert(134)//\">\n\n %>/\nalert(2)\n\n\nXXX\n\n-->{}\n*{color:red}//[\"'`-->]]>]</div>"
727728 ]
728729 } , {
729730 "title" : "SVG" ,
Original file line number Diff line number Diff line change 141141 } ) ,
142142 '<a href="#">abc</a>'
143143 ) ;
144- assert . equal (
144+ assert . contains (
145145 DOMPurify . sanitize ( '<a href="#" class="foo <br/>">abc</a>' , {
146146 ALLOW_SELF_CLOSE_IN_ATTR : true ,
147147 } ) ,
148- '<a href="#" class="foo <br/>">abc</a>'
148+ [ '<a href="#" class="foo <br/>">abc</a>' , "<a href=\"#\" class=\"foo <br/>\">abc</a>" ]
149149 ) ;
150150 } ) ;
151151 QUnit . test ( 'Config-Flag tests: ALLOW_DATA_ATTR' , function ( assert ) {
17011701 '<img y="<x">' ,
17021702 '<img y="<x">' ,
17031703 '<img y="<x">' ,
1704+ "<img x=\"/><img src=x onerror=alert(1)>\" y=\"<x\">" ,
17041705 ] ) ;
17051706 }
17061707 ) ;
You can’t perform that action at this time.
0 commit comments