AjaxControlToolkit.Tests.HtmlSanititzer.DefaultHtmlsanitizerSanitizerTests.DivBackgroundImageWithExtraCharactersXSSTest C# (CSharp) Метод

DivBackgroundImageWithExtraCharactersXSSTest() приватный Метод

private DivBackgroundImageWithExtraCharactersXSSTest ( ) : void
Результат void
        public void DivBackgroundImageWithExtraCharactersXSSTest()
        {
            // Arrange
            DefaultHtmlSanitizer target = new DefaultHtmlSanitizer();
            Dictionary<string, string[]> elementWhiteList = CreateElementWhiteList();

            // Act
            string htmlFragment = "<DIV STYLE=\"background-image: url(&#1;javascript:alert('XSS'))\">";
            string actual = target.GetSafeHtmlFragment(htmlFragment, elementWhiteList);

            // Assert
            string expected = "<div style=\"background-image: url(&amp;#1;\"></div>";
            StringAssert.AreEqualIgnoringCase(expected, actual);
        }
DefaultHtmlsanitizerSanitizerTests