mirror of
https://github.com/httprunner/httprunner.git
synced 2026-09-04 23:16:57 +08:00
Merge pull request #532 from HttpRunner/bugfix
fix xss in response json
This commit is contained in:
+10
@@ -1,5 +1,15 @@
|
|||||||
# Release History
|
# Release History
|
||||||
|
|
||||||
|
## 2.0.5 (2019-03-04)
|
||||||
|
|
||||||
|
**Features**
|
||||||
|
|
||||||
|
- implement method to get variables and output
|
||||||
|
|
||||||
|
**Bugfixes**
|
||||||
|
|
||||||
|
- fix xss in response json
|
||||||
|
|
||||||
## 2.0.4 (2019-02-28)
|
## 2.0.4 (2019-02-28)
|
||||||
|
|
||||||
**Bugfixes**
|
**Bugfixes**
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
__title__ = 'HttpRunner'
|
__title__ = 'HttpRunner'
|
||||||
__description__ = 'One-stop solution for HTTP(S) testing.'
|
__description__ = 'One-stop solution for HTTP(S) testing.'
|
||||||
__url__ = 'https://github.com/HttpRunner/HttpRunner'
|
__url__ = 'https://github.com/HttpRunner/HttpRunner'
|
||||||
__version__ = '2.0.4'
|
__version__ = '2.0.5'
|
||||||
__author__ = 'debugtalk'
|
__author__ = 'debugtalk'
|
||||||
__author_email__ = 'mail@debugtalk.com'
|
__author_email__ = 'mail@debugtalk.com'
|
||||||
__license__ = 'Apache-2.0'
|
__license__ = 'Apache-2.0'
|
||||||
|
|||||||
@@ -266,8 +266,8 @@
|
|||||||
{% else %}
|
{% else %}
|
||||||
{{ value }}
|
{{ value }}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% elif key == "text" %}
|
{% elif key in ["text", "json"] %}
|
||||||
<pre>{{ req_resp.response.text | e }}</pre>
|
<pre>{{ value | e }}</pre>
|
||||||
{% else %}
|
{% else %}
|
||||||
{{ value }}
|
{{ value }}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|||||||
+41
-4
@@ -1,4 +1,5 @@
|
|||||||
import os
|
import os
|
||||||
|
import re
|
||||||
import shutil
|
import shutil
|
||||||
import time
|
import time
|
||||||
import unittest
|
import unittest
|
||||||
@@ -185,10 +186,6 @@ class TestHttpRunner(ApiServerUnittest):
|
|||||||
{
|
{
|
||||||
"config": {
|
"config": {
|
||||||
'name': "post data",
|
'name': "post data",
|
||||||
'request': {
|
|
||||||
'base_url': '',
|
|
||||||
'headers': {'User-Agent': 'python-requests/2.18.4'}
|
|
||||||
},
|
|
||||||
'variables': []
|
'variables': []
|
||||||
},
|
},
|
||||||
"teststeps": [
|
"teststeps": [
|
||||||
@@ -198,6 +195,7 @@ class TestHttpRunner(ApiServerUnittest):
|
|||||||
"url": "{}/post".format(HTTPBIN_SERVER),
|
"url": "{}/post".format(HTTPBIN_SERVER),
|
||||||
"method": "POST",
|
"method": "POST",
|
||||||
"headers": {
|
"headers": {
|
||||||
|
"User-Agent": "python-requests/2.18.4",
|
||||||
"Content-Type": "application/json"
|
"Content-Type": "application/json"
|
||||||
},
|
},
|
||||||
"data": "abc"
|
"data": "abc"
|
||||||
@@ -508,6 +506,45 @@ class TestHttpRunner(ApiServerUnittest):
|
|||||||
# self.runner.run(testcase_file_path)
|
# self.runner.run(testcase_file_path)
|
||||||
# self.assertTrue(self.runner.summary["success"])
|
# self.assertTrue(self.runner.summary["success"])
|
||||||
|
|
||||||
|
def test_html_report_xss(self):
|
||||||
|
testcases = [
|
||||||
|
{
|
||||||
|
"config": {
|
||||||
|
'name': "post data"
|
||||||
|
},
|
||||||
|
"teststeps": [
|
||||||
|
{
|
||||||
|
"name": "post data",
|
||||||
|
"request": {
|
||||||
|
"url": "{}/anything".format(HTTPBIN_SERVER),
|
||||||
|
"method": "POST",
|
||||||
|
"headers": {
|
||||||
|
"Content-Type": "application/json"
|
||||||
|
},
|
||||||
|
"json": {
|
||||||
|
'success': False,
|
||||||
|
"person": "<img src=x onerror=alert(1)>"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"validate": [
|
||||||
|
{"eq": ["status_code", 200]}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
tests_mapping = {
|
||||||
|
"testcases": testcases
|
||||||
|
}
|
||||||
|
report_path = self.runner.run(tests_mapping)
|
||||||
|
with open(report_path) as f:
|
||||||
|
content = f.read()
|
||||||
|
m = re.findall(
|
||||||
|
re.escape(""person": "<img src=x onerror=alert(1)>""),
|
||||||
|
content
|
||||||
|
)
|
||||||
|
self.assertEqual(len(m), 2)
|
||||||
|
|
||||||
|
|
||||||
class TestApi(ApiServerUnittest):
|
class TestApi(ApiServerUnittest):
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user