123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462 |
- <?php
- /**
- * SanitizeTest file
- *
- * PHP 5
- *
- * CakePHP(tm) Tests <http://book.cakephp.org/2.0/en/development/testing.html>
- * Copyright 2005-2012, Cake Software Foundation, Inc. (http://cakefoundation.org)
- *
- * Licensed under The MIT License
- * Redistributions of files must retain the above copyright notice
- *
- * @copyright Copyright 2005-2012, Cake Software Foundation, Inc. (http://cakefoundation.org)
- * @link http://book.cakephp.org/2.0/en/development/testing.html CakePHP(tm) Tests
- * @package Cake.Test.Case.Utility
- * @since CakePHP(tm) v 1.2.0.5428
- * @license MIT License (http://www.opensource.org/licenses/mit-license.php)
- */
- App::uses('Sanitize', 'Utility');
- /**
- * DataTest class
- *
- * @package Cake.Test.Case.Utility
- */
- class SanitizeDataTest extends CakeTestModel {
- /**
- * name property
- *
- * @var string 'SanitizeDataTest'
- */
- public $name = 'SanitizeDataTest';
- /**
- * useTable property
- *
- * @var string 'data_tests'
- */
- public $useTable = 'data_tests';
- }
- /**
- * Article class
- *
- * @package Cake.Test.Case.Utility
- */
- class SanitizeArticle extends CakeTestModel {
- /**
- * name property
- *
- * @var string 'Article'
- */
- public $name = 'SanitizeArticle';
- /**
- * useTable property
- *
- * @var string 'articles'
- */
- public $useTable = 'articles';
- }
- /**
- * SanitizeTest class
- *
- * @package Cake.Test.Case.Utility
- */
- class SanitizeTest extends CakeTestCase {
- /**
- * autoFixtures property
- *
- * @var bool false
- */
- public $autoFixtures = false;
- /**
- * fixtures property
- *
- * @var array
- */
- public $fixtures = array('core.data_test', 'core.article');
- /**
- * testEscapeAlphaNumeric method
- *
- * @return void
- */
- public function testEscapeAlphaNumeric() {
- $resultAlpha = Sanitize::escape('abc', 'test');
- $this->assertEquals('abc', $resultAlpha);
- $resultNumeric = Sanitize::escape('123', 'test');
- $this->assertEquals('123', $resultNumeric);
- $resultNumeric = Sanitize::escape(1234, 'test');
- $this->assertEquals(1234, $resultNumeric);
- $resultNumeric = Sanitize::escape(1234.23, 'test');
- $this->assertEquals(1234.23, $resultNumeric);
- $resultNumeric = Sanitize::escape('#1234.23', 'test');
- $this->assertEquals('#1234.23', $resultNumeric);
- $resultNull = Sanitize::escape(null, 'test');
- $this->assertEquals(null, $resultNull);
- $resultNull = Sanitize::escape(false, 'test');
- $this->assertEquals(false, $resultNull);
- $resultNull = Sanitize::escape(true, 'test');
- $this->assertEquals(true, $resultNull);
- }
- /**
- * testClean method
- *
- * @return void
- */
- public function testClean() {
- $string = 'test & "quote" \'other\' ;.$ symbol.' . "\r" . 'another line';
- $expected = 'test & "quote" 'other' ;.$ symbol.another line';
- $result = Sanitize::clean($string, array('connection' => 'test'));
- $this->assertEquals($expected, $result);
- $string = 'test & "quote" \'other\' ;.$ symbol.' . "\r" . 'another line';
- $expected = 'test & ' . Sanitize::escape('"quote"', 'test') . ' ' . Sanitize::escape('\'other\'', 'test') . ' ;.$ symbol.another line';
- $result = Sanitize::clean($string, array('encode' => false, 'connection' => 'test'));
- $this->assertEquals($expected, $result);
- $string = 'test & "quote" \'other\' ;.$ \\$ symbol.' . "\r" . 'another line';
- $expected = 'test & "quote" \'other\' ;.$ $ symbol.another line';
- $result = Sanitize::clean($string, array('encode' => false, 'escape' => false, 'connection' => 'test'));
- $this->assertEquals($expected, $result);
- $string = 'test & "quote" \'other\' ;.$ \\$ symbol.' . "\r" . 'another line';
- $expected = 'test & "quote" \'other\' ;.$ \\$ symbol.another line';
- $result = Sanitize::clean($string, array('encode' => false, 'escape' => false, 'dollar' => false, 'connection' => 'test'));
- $this->assertEquals($expected, $result);
- $string = 'test & "quote" \'other\' ;.$ symbol.' . "\r" . 'another line';
- $expected = 'test & "quote" \'other\' ;.$ symbol.' . "\r" . 'another line';
- $result = Sanitize::clean($string, array('encode' => false, 'escape' => false, 'carriage' => false, 'connection' => 'test'));
- $this->assertEquals($expected, $result);
- $array = array(array('test & "quote" \'other\' ;.$ symbol.' . "\r" . 'another line'));
- $expected = array(array('test & "quote" 'other' ;.$ symbol.another line'));
- $result = Sanitize::clean($array, array('connection' => 'test'));
- $this->assertEquals($expected, $result);
- $array = array(array('test & "quote" \'other\' ;.$ \\$ symbol.' . "\r" . 'another line'));
- $expected = array(array('test & "quote" \'other\' ;.$ $ symbol.another line'));
- $result = Sanitize::clean($array, array('encode' => false, 'escape' => false, 'connection' => 'test'));
- $this->assertEquals($expected, $result);
- $array = array(array('test odd Ä spacesé'));
- $expected = array(array('test odd Ä spacesé'));
- $result = Sanitize::clean($array, array('odd_spaces' => false, 'escape' => false, 'connection' => 'test'));
- $this->assertEquals($expected, $result);
- $array = array(array('\\$', array('key' => 'test & "quote" \'other\' ;.$ \\$ symbol.' . "\r" . 'another line')));
- $expected = array(array('$', array('key' => 'test & "quote" \'other\' ;.$ $ symbol.another line')));
- $result = Sanitize::clean($array, array('encode' => false, 'escape' => false, 'connection' => 'test'));
- $this->assertEquals($expected, $result);
- $string = '';
- $expected = '';
- $result = Sanitize::clean($string, array('connection' => 'test'));
- $this->assertEquals($expected, $string);
- $data = array(
- 'Grant' => array(
- 'title' => '2 o clock grant',
- 'grant_peer_review_id' => 3,
- 'institution_id' => 5,
- 'created_by' => 1,
- 'modified_by' => 1,
- 'created' => '2010-07-15 14:11:00',
- 'modified' => '2010-07-19 10:45:41'
- ),
- 'GrantsMember' => array(
- 0 => array(
- 'id' => 68,
- 'grant_id' => 120,
- 'member_id' => 16,
- 'program_id' => 29,
- 'pi_percent_commitment' => 1
- )
- )
- );
- $result = Sanitize::clean($data, array('connection' => 'test'));
- $this->assertEquals($data, $result);
- }
- /**
- * testHtml method
- *
- * @return void
- */
- public function testHtml() {
- $string = '<p>This is a <em>test string</em> & so is this</p>';
- $expected = 'This is a test string & so is this';
- $result = Sanitize::html($string, array('remove' => true));
- $this->assertEquals($expected, $result);
- $string = 'The "lazy" dog \'jumped\' & flew over the moon. If (1+1) = 2 <em>is</em> true, (2-1) = 1 is also true';
- $expected = 'The "lazy" dog 'jumped' & flew over the moon. If (1+1) = 2 <em>is</em> true, (2-1) = 1 is also true';
- $result = Sanitize::html($string);
- $this->assertEquals($expected, $result);
- $string = 'The "lazy" dog \'jumped\'';
- $expected = 'The "lazy" dog \'jumped\'';
- $result = Sanitize::html($string, array('quotes' => ENT_COMPAT));
- $this->assertEquals($expected, $result);
- $string = 'The "lazy" dog \'jumped\'';
- $result = Sanitize::html($string, array('quotes' => ENT_NOQUOTES));
- $this->assertEquals($string, $result);
- $string = 'The "lazy" dog \'jumped\' & flew over the moon. If (1+1) = 2 <em>is</em> true, (2-1) = 1 is also true';
- $expected = 'The "lazy" dog 'jumped' & flew over the moon. If (1+1) = 2 <em>is</em> true, (2-1) = 1 is also true';
- $result = Sanitize::html($string);
- $this->assertEquals($expected, $result);
- $string = 'The "lazy" dog & his friend Apple® conquered the world';
- $expected = 'The "lazy" dog & his friend Apple&reg; conquered the world';
- $result = Sanitize::html($string);
- $this->assertEquals($expected, $result);
- $string = 'The "lazy" dog & his friend Apple® conquered the world';
- $expected = 'The "lazy" dog & his friend Apple® conquered the world';
- $result = Sanitize::html($string, array('double' => false));
- $this->assertEquals($expected, $result);
- }
- /**
- * testStripWhitespace method
- *
- * @return void
- */
- public function testStripWhitespace() {
- $string = "This sentence \t\t\t has lots of \n\n white\nspace \rthat \r\n needs to be \t \n trimmed.";
- $expected = "This sentence has lots of whitespace that needs to be trimmed.";
- $result = Sanitize::stripWhitespace($string);
- $this->assertEquals($expected, $result);
- $text = 'I love ßá†ö√ letters.';
- $result = Sanitize::stripWhitespace($text);
- $expected = 'I love ßá†ö√ letters.';
- $this->assertEquals($expected, $result);
- }
- /**
- * testParanoid method
- *
- * @return void
- */
- public function testParanoid() {
- $string = 'I would like to !%@#% & dance & sing ^$&*()-+';
- $expected = 'Iwouldliketodancesing';
- $result = Sanitize::paranoid($string);
- $this->assertEquals($expected, $result);
- $string = array('This |s th% s0ng that never ends it g*es',
- 'on and on my friends, b^ca#use it is the',
- 'so&g th===t never ends.');
- $expected = array('This s th% s0ng that never ends it g*es',
- 'on and on my friends bcause it is the',
- 'sog tht never ends.');
- $result = Sanitize::paranoid($string, array('%', '*', '.', ' '));
- $this->assertEquals($expected, $result);
- $string = "anything' OR 1 = 1";
- $expected = 'anythingOR11';
- $result = Sanitize::paranoid($string);
- $this->assertEquals($expected, $result);
- $string = "x' AND email IS NULL; --";
- $expected = 'xANDemailISNULL';
- $result = Sanitize::paranoid($string);
- $this->assertEquals($expected, $result);
- $string = "x' AND 1=(SELECT COUNT(*) FROM users); --";
- $expected = "xAND1SELECTCOUNTFROMusers";
- $result = Sanitize::paranoid($string);
- $this->assertEquals($expected, $result);
- $string = "x'; DROP TABLE members; --";
- $expected = "xDROPTABLEmembers";
- $result = Sanitize::paranoid($string);
- $this->assertEquals($expected, $result);
- }
- /**
- * testStripImages method
- *
- * @return void
- */
- public function testStripImages() {
- $string = '<img src="/img/test.jpg" alt="my image" />';
- $expected = 'my image<br />';
- $result = Sanitize::stripImages($string);
- $this->assertEquals($expected, $result);
- $string = '<img src="javascript:alert(\'XSS\');" />';
- $expected = '';
- $result = Sanitize::stripImages($string);
- $this->assertEquals($expected, $result);
- $string = '<a href="http://www.badsite.com/phising"><img src="/img/test.jpg" alt="test image alt" title="test image title" id="myImage" class="image-left"/></a>';
- $expected = '<a href="http://www.badsite.com/phising">test image alt</a><br />';
- $result = Sanitize::stripImages($string);
- $this->assertEquals($expected, $result);
- $string = '<a onclick="medium()" href="http://example.com"><img src="foobar.png" onclick="evilFunction(); return false;"/></a>';
- $expected = '<a onclick="medium()" href="http://example.com"></a>';
- $result = Sanitize::stripImages($string);
- $this->assertEquals($expected, $result);
- }
- /**
- * testStripScripts method
- *
- * @return void
- */
- public function testStripScripts() {
- $string = '<link href="/css/styles.css" media="screen" rel="stylesheet" />';
- $expected = '';
- $result = Sanitize::stripScripts($string);
- $this->assertEquals($expected, $result);
- $string = '<link href="/css/styles.css" media="screen" rel="stylesheet" />' . "\n" .
- '<link rel="icon" href="/favicon.ico" type="image/x-icon" />' . "\n" .
- '<link rel="shortcut icon" href="/favicon.ico" type="image/x-icon" />' . "\n" .
- '<link rel="alternate" href="/feed.xml" title="RSS Feed" type="application/rss+xml" />';
- $expected = "\n" . '<link rel="icon" href="/favicon.ico" type="image/x-icon" />' . "\n" .
- '<link rel="shortcut icon" href="/favicon.ico" type="image/x-icon" />' . "\n" .
- '<link rel="alternate" href="/feed.xml" title="RSS Feed" type="application/rss+xml" />';
- $result = Sanitize::stripScripts($string);
- $this->assertEquals($expected, $result);
- $string = '<script type="text/javascript"> alert("hacked!");</script>';
- $expected = '';
- $result = Sanitize::stripScripts($string);
- $this->assertEquals($expected, $result);
- $string = '<script> alert("hacked!");</script>';
- $expected = '';
- $result = Sanitize::stripScripts($string);
- $this->assertEquals($expected, $result);
- $string = '<style>#content { display:none; }</style>';
- $expected = '';
- $result = Sanitize::stripScripts($string);
- $this->assertEquals($expected, $result);
- $string = '<style type="text/css"><!-- #content { display:none; } --></style>';
- $expected = '';
- $result = Sanitize::stripScripts($string);
- $this->assertEquals($expected, $result);
- $string = <<<HTML
- text
- <style type="text/css">
- <!--
- #content { display:none; }
- -->
- </style>
- text
- HTML;
- $expected = "text\n\ntext";
- $result = Sanitize::stripScripts($string);
- $this->assertTextEquals($expected, $result);
- $string = <<<HTML
- text
- <script type="text/javascript">
- <!--
- alert('wooo');
- -->
- </script>
- text
- HTML;
- $expected = "text\n\ntext";
- $result = Sanitize::stripScripts($string);
- $this->assertTextEquals($expected, $result);
- }
- /**
- * testStripAll method
- *
- * @return void
- */
- public function testStripAll() {
- $string = '<img """><script>alert("xss")</script>"/>';
- $expected = '"/>';
- $result = Sanitize::stripAll($string);
- $this->assertEquals($expected, $result);
- $string = '<IMG SRC=javascript:alert('XSS')>';
- $expected = '';
- $result = Sanitize::stripAll($string);
- $this->assertEquals($expected, $result);
- $string = '<<script>alert("XSS");//<</script>';
- $expected = '<';
- $result = Sanitize::stripAll($string);
- $this->assertEquals($expected, $result);
- $string = '<img src="http://google.com/images/logo.gif" onload="window.location=\'http://sam.com/\'" />' . "\n" .
- "<p>This is ok \t\n text</p>\n" .
- '<link rel="stylesheet" href="/css/master.css" type="text/css" media="screen" title="my sheet" charset="utf-8">' . "\n" .
- '<script src="xss.js" type="text/javascript" charset="utf-8"></script>';
- $expected = '<p>This is ok text</p>';
- $result = Sanitize::stripAll($string);
- $this->assertEquals($expected, $result);
- }
- /**
- * testStripTags method
- *
- * @return void
- */
- public function testStripTags() {
- $string = '<h2>Headline</h2><p><a href="http://example.com">My Link</a> could go to a bad site</p>';
- $expected = 'Headline<p>My Link could go to a bad site</p>';
- $result = Sanitize::stripTags($string, 'h2', 'a');
- $this->assertEquals($expected, $result);
- $string = '<script type="text/javascript" src="http://evildomain.com"> </script>';
- $expected = ' ';
- $result = Sanitize::stripTags($string, 'script');
- $this->assertEquals($expected, $result);
- $string = '<h2>Important</h2><p>Additional information here <a href="/about"><img src="/img/test.png" /></a>. Read even more here</p>';
- $expected = 'Important<p>Additional information here <img src="/img/test.png" />. Read even more here</p>';
- $result = Sanitize::stripTags($string, 'h2', 'a');
- $this->assertEquals($expected, $result);
- $string = '<h2>Important</h2><p>Additional information here <a href="/about"><img src="/img/test.png" /></a>. Read even more here</p>';
- $expected = 'Important<p>Additional information here . Read even more here</p>';
- $result = Sanitize::stripTags($string, 'h2', 'a', 'img');
- $this->assertEquals($expected, $result);
- $string = '<b>Important message!</b><br>This message will self destruct!';
- $expected = 'Important message!<br>This message will self destruct!';
- $result = Sanitize::stripTags($string, 'b');
- $this->assertEquals($expected, $result);
- $string = '<b>Important message!</b><br />This message will self destruct!';
- $expected = 'Important message!<br />This message will self destruct!';
- $result = Sanitize::stripTags($string, 'b');
- $this->assertEquals($expected, $result);
- $string = '<h2 onclick="alert(\'evil\'); onmouseover="badness()">Important</h2><p>Additional information here <a href="/about"><img src="/img/test.png" /></a>. Read even more here</p>';
- $expected = 'Important<p>Additional information here . Read even more here</p>';
- $result = Sanitize::stripTags($string, 'h2', 'a', 'img');
- $this->assertEquals($expected, $result);
- }
- }
|