From 0dee528adb56b2e8d195d251c26ca8cae08b88fc Mon Sep 17 00:00:00 2001 From: Aleksander Machniak Date: Fri, 24 Aug 2018 12:33:15 +0200 Subject: [PATCH] Add test for #6410 --- tests/MailFunc.php | 1 + tests/src/htmlxss.txt | 2 ++ 2 files changed, 3 insertions(+) diff --git a/tests/MailFunc.php b/tests/MailFunc.php index 2689001e2..fb4749196 100644 --- a/tests/MailFunc.php +++ b/tests/MailFunc.php @@ -75,6 +75,7 @@ class MailFunc extends PHPUnit_Framework_TestCase $this->assertNotRegExp('/src="skins/', $washed, "Remove local references"); $this->assertNotRegExp('/\son[a-z]+/', $washed, "Remove on* attributes"); + $this->assertNotContains('onload', $washed, "Handle invalid style"); $html = rcmail_html4inline($washed, array('container_id' => 'foo')); $this->assertNotRegExp('/onclick="return rcmail.command(\'compose\',\'xss@somehost.net\',this)"/', $html, "Clean mailto links"); diff --git a/tests/src/htmlxss.txt b/tests/src/htmlxss.txt index f6c43e353..a81c5776e 100644 --- a/tests/src/htmlxss.txt +++ b/tests/src/htmlxss.txt @@ -18,5 +18,7 @@ Have a nice Christmas time.
Thomas

+ +