Skip to content
Snippets Groups Projects
Commit a47bf769 authored by catch's avatar catch
Browse files

Issue #2503063 by alexpott, Lendude: Removing XssTest causes test failures due...

Issue #2503063 by alexpott, Lendude: Removing XssTest causes test failures due to UrlHelper's static $allowedProtocols
parent b5208e28
No related branches found
No related tags found
36 merge requests!7452Issue #1797438. HTML5 validation is preventing form submit and not fully...,!54479.5.x SF update,!5014Issue #3071143: Table Render Array Example Is Incorrect,!4868Issue #1428520: Improve menu parent link selection,!4289Issue #1344552 by marcingy, Niklas Fiekas, Ravi.J, aleevas, Eduardo Morales...,!4114Issue #2707291: Disable body-level scrolling when a dialog is open as a modal,!4100Issue #3249600: Add support for PHP 8.1 Enums as allowed values for list_* data types,!3630Issue #2815301 by Chi, DanielVeza, kostyashupenko, smustgrave: Allow to create...,!3600Issue #3344629: Passing null to parameter #1 ($haystack) of type string is deprecated,!3291Issue #3336463: Rewrite rules for gzipped CSS and JavaScript aggregates never match,!3102Issue #3164428 by DonAtt, longwave, sahil.goyal, Anchal_gupta, alexpott: Use...,!2378Issue #2875033: Optimize joins and table selection in SQL entity query implementation,!2334Issue #3228209: Add hasRole() method to AccountInterface,!2074Issue #2707689: NodeForm::actions() checks for delete access on new entities,!2062Issue #3246454: Add weekly granularity to views date sort,!1591Issue #3199697: Add JSON:API Translation experimental module,!1484Exposed filters get values from URL when Ajax is on,!1255Issue #3238922: Refactor (if feasible) uses of the jQuery serialize function to use vanillaJS,!1254Issue #3238915: Refactor (if feasible) uses of the jQuery ready function to use VanillaJS,!1162Issue #3100350: Unable to save '/' root path alias,!1105Issue #3025039: New non translatable field on translatable content throws error,!1073issue #3191727: Focus states on mobile second level navigation items fixed,!10223132456: Fix issue where views instances are emptied before an ajax request is complete,!957Added throwing of InvalidPluginDefinitionException from getDefinition().,!925Issue #2339235: Remove taxonomy hard dependency on node module,!877Issue #2708101: Default value for link text is not saved,!873Issue #2875228: Site install not using batch API service,!872Draft: Issue #3221319: Race condition when creating menu links and editing content deletes menu links,!844Resolve #3036010 "Updaters",!712Issue #2909128: Autocomplete intermittent on Chrome Android,!617Issue #3043725: Provide a Entity Handler for user cancelation,!579Issue #2230909: Simple decimals fail to pass validation,!560Move callback classRemove outside of the loop,!555Issue #3202493,!485Sets the autocomplete attribute for username/password input field on login form.,!30Issue #3182188: Updates composer usage to point at ./vendor/bin/composer
...@@ -18,8 +18,13 @@ class LinkExternalProtocolsConstraintValidatorTest extends UnitTestCase { ...@@ -18,8 +18,13 @@ class LinkExternalProtocolsConstraintValidatorTest extends UnitTestCase {
/** /**
* @covers ::validate * @covers ::validate
* @dataProvider providerValidate * @dataProvider providerValidate
* @runInSeparateProcess
*/ */
public function testValidate($value, $valid) { public function testValidate($url, $valid) {
$link = $this->createMock('Drupal\link\LinkItemInterface');
$link->expects($this->any())
->method('getUrl')
->willReturn(Url::fromUri($url));
$context = $this->createMock(ExecutionContextInterface::class); $context = $this->createMock(ExecutionContextInterface::class);
if ($valid) { if ($valid) {
...@@ -38,7 +43,7 @@ public function testValidate($value, $valid) { ...@@ -38,7 +43,7 @@ public function testValidate($value, $valid) {
$validator = new LinkExternalProtocolsConstraintValidator(); $validator = new LinkExternalProtocolsConstraintValidator();
$validator->initialize($context); $validator->initialize($context);
$validator->validate($value, $constraint); $validator->validate($link, $constraint);
} }
/** /**
...@@ -56,15 +61,6 @@ public function providerValidate() { ...@@ -56,15 +61,6 @@ public function providerValidate() {
// Invalid protocols. // Invalid protocols.
$data[] = ['ftp://ftp.funet.fi/pub/standards/RFC/rfc959.txt', FALSE]; $data[] = ['ftp://ftp.funet.fi/pub/standards/RFC/rfc959.txt', FALSE];
foreach ($data as &$single_data) {
$url = Url::fromUri($single_data[0]);
$link = $this->createMock('Drupal\link\LinkItemInterface');
$link->expects($this->any())
->method('getUrl')
->willReturn($url);
$single_data[0] = $link;
}
return $data; return $data;
} }
......
...@@ -449,6 +449,8 @@ public static function providerTestIsExternal() { ...@@ -449,6 +449,8 @@ public static function providerTestIsExternal() {
* Expected escaped value. * Expected escaped value.
* @param array $protocols * @param array $protocols
* Protocols to allow. * Protocols to allow.
*
* @runInSeparateProcess
*/ */
public function testFilterBadProtocol($uri, $expected, $protocols) { public function testFilterBadProtocol($uri, $expected, $protocols) {
UrlHelper::setAllowedProtocols($protocols); UrlHelper::setAllowedProtocols($protocols);
...@@ -488,6 +490,8 @@ public static function providerTestFilterBadProtocol() { ...@@ -488,6 +490,8 @@ public static function providerTestFilterBadProtocol() {
* Expected escaped value. * Expected escaped value.
* @param array $protocols * @param array $protocols
* Protocols to allow. * Protocols to allow.
*
* @runInSeparateProcess
*/ */
public function testStripDangerousProtocols($uri, $expected, $protocols) { public function testStripDangerousProtocols($uri, $expected, $protocols) {
UrlHelper::setAllowedProtocols($protocols); UrlHelper::setAllowedProtocols($protocols);
......
...@@ -23,6 +23,8 @@ ...@@ -23,6 +23,8 @@
* Relevant CVEs: * Relevant CVEs:
* - CVE-2002-1806, ~CVE-2005-0682, ~CVE-2005-2106, CVE-2005-3973, * - CVE-2002-1806, ~CVE-2005-0682, ~CVE-2005-2106, CVE-2005-3973,
* CVE-2006-1226 (= rev. 1.112?), CVE-2008-0273, CVE-2008-3740. * CVE-2006-1226 (= rev. 1.112?), CVE-2008-0273, CVE-2008-3740.
*
* @runTestsInSeparateProcesses
*/ */
class XssTest extends TestCase { class XssTest extends TestCase {
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment