diff --git a/tests/MailFunc.php b/tests/MailFunc.php index 2689001e2..fb4749196 100644 --- a/tests/MailFunc.php +++ b/tests/MailFunc.php @@ -75,6 +75,7 @@ class MailFunc extends PHPUnit_Framework_TestCase $this->assertNotRegExp('/src="skins/', $washed, "Remove local references"); $this->assertNotRegExp('/\son[a-z]+/', $washed, "Remove on* attributes"); + $this->assertNotContains('onload', $washed, "Handle invalid style"); $html = rcmail_html4inline($washed, array('container_id' => 'foo')); $this->assertNotRegExp('/onclick="return rcmail.command(\'compose\',\'xss@somehost.net\',this)"/', $html, "Clean mailto links"); diff --git a/tests/src/htmlxss.txt b/tests/src/htmlxss.txt index f6c43e353..a81c5776e 100644 --- a/tests/src/htmlxss.txt +++ b/tests/src/htmlxss.txt @@ -18,5 +18,7 @@ Have a nice Christmas time.
Thomas

+ +