1
0
mirror of https://github.com/phpbb/phpbb.git synced 2025-08-09 10:16:36 +02:00

[ticket/16250] Add a service to check BBCodes safeness

PHPBB3-16250
This commit is contained in:
JoshyPHP
2019-12-13 01:46:09 +01:00
parent 5be4cca408
commit 2926ceba6a
7 changed files with 246 additions and 5 deletions

View File

@@ -43,4 +43,44 @@ class phpbb_functional_acp_bbcodes_test extends phpbb_functional_test_case
$this->assertContains('<div>c</div>', $html);
$this->assertContains('<div>d</div>', $html);
}
/**
* @dataProvider get_bbcode_error_tests
*/
public function test_bbcode_error($match, $tpl, $error)
{
$this->login();
$this->admin_login();
$crawler = self::request('GET', 'adm/index.php?i=acp_bbcodes&sid=' . $this->sid . '&mode=bbcodes&action=add');
$form = $crawler->selectButton('Submit')->form([
'bbcode_match' => $match,
'bbcode_tpl' => $tpl
]);
$crawler = self::submit($form);
$text = $crawler->filter('.errorbox')->text();
$this->assertStringContainsString($error, $text);
}
public function get_bbcode_error_tests()
{
return [
[
'XXX',
'',
'BBCode is constructed in an invalid form'
],
[
'[x]{TEXT}[/x]',
'<xsl:invalid',
'template is invalid'
],
[
'[x]{TEXT}[/x]',
'<script>{TEXT}</script>',
'unsafe'
],
];
}
}