2 /*********************************************************************************
3 * SugarCRM Community Edition is a customer relationship management program developed by
4 * SugarCRM, Inc. Copyright (C) 2004-2011 SugarCRM Inc.
6 * This program is free software; you can redistribute it and/or modify it under
7 * the terms of the GNU Affero General Public License version 3 as published by the
8 * Free Software Foundation with the addition of the following permission added
9 * to Section 15 as permitted in Section 7(a): FOR ANY PART OF THE COVERED WORK
10 * IN WHICH THE COPYRIGHT IS OWNED BY SUGARCRM, SUGARCRM DISCLAIMS THE WARRANTY
11 * OF NON INFRINGEMENT OF THIRD PARTY RIGHTS.
13 * This program is distributed in the hope that it will be useful, but WITHOUT
14 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
15 * FOR A PARTICULAR PURPOSE. See the GNU Affero General Public License for more
18 * You should have received a copy of the GNU Affero General Public License along with
19 * this program; if not, see http://www.gnu.org/licenses or write to the Free
20 * Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
23 * You can contact SugarCRM, Inc. headquarters at 10050 North Wolfe Road,
24 * SW2-130, Cupertino, CA 95014, USA. or at email address contact@sugarcrm.com.
26 * The interactive user interfaces in modified source and object code versions
27 * of this program must display Appropriate Legal Notices, as required under
28 * Section 5 of the GNU Affero General Public License version 3.
30 * In accordance with Section 7(b) of the GNU Affero General Public License version 3,
31 * these Appropriate Legal Notices must retain the display of the "Powered by
32 * SugarCRM" logo. If the display of the logo is not reasonably feasible for
33 * technical reasons, the Appropriate Legal Notices must display the words
34 * "Powered by SugarCRM".
35 ********************************************************************************/
38 require_once 'include/utils.php';
40 class XssTest extends Sugar_PHPUnit_Framework_TestCase
42 public function xssData()
45 array("some data", "some data"),
47 array("test <a href=\"http://www.digitalbrandexpressions.com\">link</a>", "test <a href=\"http://www.digitalbrandexpressions.com\">link</a>"),
48 array("some data<script>alert('xss!')</script>", "some dataalert('xss!')"),
49 array("some data<script src=\" http://localhost/xss.js\"></script>", "some data"),
50 array("some data<applet></applet><script src=\" http://localhost/xss.js\"></script>", "some data"),
51 array('some data before<img alt="<script>" src="http://www.symbolset.org/images/peace-sign-2.jpg"; onload="alert(35)" width="1" height="1"/>some data after', 'some data before<img alt="<script>" src="http://www.symbolset.org/images/peace-sign-2.jpg"; width="1" height="1"/>some data after'),
52 array('some data before<img src="http://www.symbolset.org/images/peace-sign-2.jpg"; onload="alert(35)" width="1" height="1"/>some data after', 'some data before<img src="http://www.symbolset.org/images/peace-sign-2.jpg"; width="1" height="1"/>some data after'),
53 array('some data before<img src="http://www.symbolset.org/images/peace-sign-2.jpg"; width="1" height="1"/>some data after', 'some data before<img src="http://www.symbolset.org/images/peace-sign-2.jpg"; width="1" height="1"/>some data after'),
54 array('<div style="font-family:Calibri;">Roger Smith</div>', '<div style="font-family:Calibri;">Roger Smith</div>'),
55 array('some data before<img onmouseover onload onmouseover=\'alert(8)\' src="http://www.docspopuli.org/images/Symbol.jpg";\'/>some data after', 'some data before<img onmouseover onload src="http://www.docspopuli.org/images/Symbol.jpg";\'/>some data after'),
60 protected function clean($str) {
61 $potentials = clean_xss($str, false);
62 if(is_array($potentials) && !empty($potentials)) {
63 foreach($potentials as $bad) {
64 $str = str_replace($bad, "", $str);
71 * @dataProvider xssData
73 public function testXssFilter($before, $after)
75 $this->assertEquals($after, $this->clean($before));
79 * @dataProvider xssData
81 public function testXssFilterBean($before, $after)
83 $bean = new EmailTemplate();
84 $bean->body_html = to_html($before);
86 $this->assertEquals(to_html($after), $bean->body_html);