Welcome Guest! To enable all features please Login or Register.

Notification

Icon
Error

TimeLine.html is not escaping HTML for test name
GreenMoose
#1 Posted : Wednesday, January 9, 2019 7:41:52 AM(UTC)
Rank: Advanced Member

Groups: Registered
Joined: 6/17/2012(UTC)
Posts: 503

Thanks: 142 times
Was thanked: 66 time(s) in 64 post(s)
[NCrunch Console Tool v3.23.0.9]

The generated TimeLine.html does not seem to escape HTML so e.g. below results in a popup "123" when viewed in a browser (or in a TeamCity tab):
Code:

                   <div class="passingtest"><div style="display:inline;margin-left: 10px;"><i data-feather="check"></i> MiscFixtures.GetReminderTextReturnsHtmlEncodedMessage("test reminder")</div></div>
                   <div class="passingtest"><div style="display:inline;margin-left: 10px;"><i data-feather="check"></i> MiscFixtures.*</div></div>
                   <div class="passingtest"><div style="display:inline;margin-left: 10px;"><i data-feather="check"></i> MiscFixtures.GetReminderTextReturnsHtmlEncodedMessage("test reminder<br/><script>alert(123);</script>")</div></div>

1 user thanked GreenMoose for this useful post.
michaelkroes on 1/9/2019(UTC)
michaelkroes
#2 Posted : Wednesday, January 9, 2019 7:51:12 AM(UTC)
Rank: NCrunch Developer

Groups: Registered
Joined: 9/22/2017(UTC)
Posts: 280
Location: Netherlands

Thanks: 124 times
Was thanked: 63 time(s) in 60 post(s)
Good catch! I'll have a look :)
1 user thanked michaelkroes for this useful post.
GreenMoose on 1/9/2019(UTC)
michaelkroes
#3 Posted : Wednesday, January 9, 2019 8:33:22 AM(UTC)
Rank: NCrunch Developer

Groups: Registered
Joined: 9/22/2017(UTC)
Posts: 280
Location: Netherlands

Thanks: 124 times
Was thanked: 63 time(s) in 60 post(s)
This is fixed in the upcoming release. Thanks again!
1 user thanked michaelkroes for this useful post.
GreenMoose on 1/9/2019(UTC)
Users browsing this topic
Guest
Forum Jump  
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.

YAF | YAF © 2003-2011, Yet Another Forum.NET
This page was generated in 0.017 seconds.
Trial NCrunch
Take NCrunch for a spin
Do your fingers a favour and supercharge your testing workflow
Free Download