diff --git a/test/test-suite.js b/test/test-suite.js index e2e5f5d0..ae9d36c6 100644 --- a/test/test-suite.js +++ b/test/test-suite.js @@ -2097,28 +2097,28 @@ QUnit.test('Test proper handling of nesting-based mXSS 1/3', function (assert) { - let dirty = `${`
`.repeat(496)}${`
`.repeat(496)}`; - let expected = `${`
`.repeat(496)}${`
`.repeat(496)}`; + let dirty = `${`
`.repeat(250)}${`
`.repeat(250)}`; + let expected = `${`
`.repeat(250)}${`
`.repeat(250)}`; let clean = DOMPurify.sanitize(dirty); assert.contains(clean, expected); - dirty = `${`
`.repeat(500)}${`
`.repeat(500)}`; - expected = `${`
`.repeat(498)}${`
`.repeat(498)}`; + dirty = `${`
`.repeat(255)}${`
`.repeat(255)}`; + expected = `${`
`.repeat(253)}${`
`.repeat(253)}`; clean = DOMPurify.sanitize(dirty); assert.contains(clean, expected); - dirty = `${`
`.repeat(502)}${`
`.repeat(502)}`; - expected = `${`
`.repeat(498)}${`
`.repeat(498)}`; + dirty = `${`
`.repeat(257)}${`
`.repeat(257)}`; + expected = `${`
`.repeat(253)}${`
`.repeat(253)}`; clean = DOMPurify.sanitize(dirty); assert.contains(clean, expected); - dirty = `