test_confirm_page_escaping.py 1.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748
  1. """The one-tap outcome prompt page escapes what it echoes (#1898).
  2. The routes only let ``good`` / ``reject`` through as the verdict, but the page
  3. renderer must not rely on that: it is served unauthenticated, and a check made
  4. in another function can be loosened without anyone looking at this one.
  5. """
  6. from __future__ import annotations
  7. from types import SimpleNamespace
  8. from starlette.requests import Request
  9. from backend.app.api.routes.archives import _render_confirm_prompt_page
  10. PAYLOAD = "<script>alert(1)</script>"
  11. def _request() -> Request:
  12. return Request(
  13. {
  14. "type": "http",
  15. "method": "GET",
  16. "path": "/api/v1/archives/confirm/tok/x",
  17. "query_string": b"",
  18. "headers": [],
  19. }
  20. )
  21. def test_an_unknown_verdict_is_escaped():
  22. archive = SimpleNamespace(print_name="Benchy", filename="benchy.3mf")
  23. page = _render_confirm_prompt_page(_request(), archive, PAYLOAD)
  24. assert PAYLOAD not in page
  25. assert "&lt;script&gt;alert(1)&lt;/script&gt;" in page
  26. def test_the_print_name_is_escaped():
  27. archive = SimpleNamespace(print_name=PAYLOAD, filename="x.3mf")
  28. page = _render_confirm_prompt_page(_request(), archive, "good")
  29. assert PAYLOAD not in page
  30. assert "Good part" in page
  31. def test_known_verdicts_keep_their_labels():
  32. archive = SimpleNamespace(print_name="Benchy", filename="benchy.3mf")
  33. assert "<strong>Good part</strong>" in _render_confirm_prompt_page(_request(), archive, "good")
  34. assert "<strong>Rejected</strong>" in _render_confirm_prompt_page(_request(), archive, "reject")