}
/**
- * Test reset_quote_tags()
+ * Test sanitize_html().
*/
- function testResetQuoteTags()
+ function testSanitizeHtml()
{
- $text = '> quote1'. PHP_EOL . ' > quote2 ' . PHP_EOL . 'noquote';
- $processedText = escape($text);
- $reversedText = reset_quote_tags($processedText);
- $this->assertEquals($text, $reversedText);
+ $input = '< script src="js.js"/>';
+ $input .= '< script attr>alert(\'xss\');</script>';
+ $input .= '<style> * { display: none }</style>';
+ $output = escape($input);
+ $input .= '<a href="#" onmouseHover="alert(\'xss\');" attr="tt">link</a>';
+ $output .= '<a href="#" attr="tt">link</a>';
+ $this->assertEquals($output, sanitize_html($input));
+ // Do not touch escaped HTML.
+ $input = escape($input);
+ $this->assertEquals($input, sanitize_html($input));
+ }
+
+ /**
+ * Test the no markdown tag.
+ */
+ function testNoMarkdownTag()
+ {
+ $str = 'All _work_ and `no play` makes Jack a *dull* boy.';
+ $data = array(
+ 'links' => array(array(
+ 'description' => $str,
+ 'tags' => NO_MD_TAG,
+ 'taglist' => array(NO_MD_TAG),
+ ))
+ );
+
+ $data = hook_markdown_render_linklist($data);
+ $this->assertEquals($str, $data['links'][0]['description']);
+
+ $data = array(
+ // Columns data
+ 'cols' => array(
+ // First, second, third.
+ 0 => array(
+ // nth link
+ 0 => array(
+ 'formatedDescription' => $str,
+ 'tags' => NO_MD_TAG,
+ 'taglist' => array(),
+ ),
+ ),
+ ),
+ );
+
+ $data = hook_markdown_render_daily($data);
+ $this->assertEquals($str, $data['cols'][0][0]['formatedDescription']);
}
}