mirror of
https://github.com/Abdulazizzn/n8n-enterprise-unlocked.git
synced 2026-09-28 04:31:43 +02:00
fix(core): Replace sanitize-html with xss in XSS validator constraint (#10479)
This commit is contained in:
@@ -16,7 +16,8 @@ describe('NoXss', () => {
|
||||
const entity = new Entity();
|
||||
|
||||
describe('Scripts', () => {
|
||||
const XSS_STRINGS = ['<script src/>', "<script>alert('xss')</script>"];
|
||||
// eslint-disable-next-line n8n-local-rules/no-unneeded-backticks
|
||||
const XSS_STRINGS = ['<script src/>', "<script>alert('xss')</script>", `<a href="#">Jack</a>`];
|
||||
|
||||
for (const str of XSS_STRINGS) {
|
||||
test(`should block ${str}`, async () => {
|
||||
@@ -69,4 +70,15 @@ describe('NoXss', () => {
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
describe('Miscellanous strings', () => {
|
||||
const VALID_MISCELLANEOUS_STRINGS = ['CI/CD'];
|
||||
|
||||
for (const str of VALID_MISCELLANEOUS_STRINGS) {
|
||||
test(`should allow ${str}`, async () => {
|
||||
entity.name = str;
|
||||
await expect(validate(entity)).resolves.toBeEmptyArray();
|
||||
});
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user