mirror of
https://github.com/YunoHost-Apps/ihatemoney_ynh.git
synced 2024-09-03 19:26:15 +02:00
parent
38d4534c69
commit
8c412b391f
1 changed files with 12 additions and 0 deletions
|
@ -911,6 +911,18 @@ class APITestCase(TestCase):
|
|||
headers=self.get_auth("raclette"))
|
||||
self.assertStatus(404, req)
|
||||
|
||||
def test_username_xss(self):
|
||||
# create a project
|
||||
#self.api_create("raclette")
|
||||
self.post_project("raclette")
|
||||
self.login("raclette")
|
||||
|
||||
# add members
|
||||
self.api_add_member("raclette", "<script>")
|
||||
|
||||
result = self.app.get('/raclette/')
|
||||
self.assertNotIn("<script>", result.data)
|
||||
|
||||
def test_weighted_bills(self):
|
||||
# create a project
|
||||
self.api_create("raclette")
|
||||
|
|
Loading…
Reference in a new issue