Skip to content

Commit 1b26162

Browse files
committed
Extra test of < and > inside quotes.
1 parent a8a0aec commit 1b26162

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

test/test_cgi.py

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -60,6 +60,8 @@ def testAddMessageBAD(self):
6060
['&lt;&lt;script &gt;&gt;alert(42);5&lt;&lt;/script &gt;&gt;'])
6161
self.assertEqual(cm([],'<a href="y">x</a>'),
6262
['&lt;a href="y"&gt;x&lt;/a&gt;'])
63+
self.assertEqual(cm([],'<a href="<y>">x</a>'),
64+
['&lt;a href="&lt;y&gt;"&gt;x&lt;/a&gt;'])
6365
self.assertEqual(cm([],'<A HREF="y">x</A>'),
6466
['&lt;A HREF="y"&gt;x&lt;/A&gt;'])
6567
self.assertEqual(cm([],'<br>x<br />'), ['&lt;br&gt;x&lt;br /&gt;'])

0 commit comments

Comments
 (0)