diff --git a/test/specs/helpers/isValidXss.spec.js b/test/specs/helpers/isValidXss.spec.js index dcfcf9d772..89be10b143 100644 --- a/test/specs/helpers/isValidXss.spec.js +++ b/test/specs/helpers/isValidXss.spec.js @@ -8,10 +8,13 @@ describe('helpers::isValidXss', function () { expect(isValidXss("xss")).toBe(true); expect(isValidXss("")).toBe(true); expect(isValidXss("onerror=alert('XSS')")).toBe(true); + expect(isValidXss("onmouseover=alert('XSS')")).toBe(true); + expect(isValidXss("onkeyup=alert('XSS')")).toBe(true); expect(isValidXss("Click Me")).toBe(true); }); it('should not detect non script tags', function() { + expect(isValidXss("only=true")).toBe(false); expect(isValidXss("/one/?foo=bar")).toBe(false); expect(isValidXss(" tags")).toBe(false); expect(isValidXss("")).toBe(false);