From fc092b032ac07dab2686f187f37151bfe994cd1a Mon Sep 17 00:00:00 2001 From: Erlend Oftedal Date: Fri, 28 Sep 2012 22:17:09 +0200 Subject: [PATCH] Fixing data URI tests --- app/models/test_case.rb | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/app/models/test_case.rb b/app/models/test_case.rb index d7bdb0a..9949e09 100644 --- a/app/models/test_case.rb +++ b/app/models/test_case.rb @@ -66,15 +66,15 @@ def self.load() end def self.load_1_0() self.create_testcases("stylesheet", "style-src", "linked_style.erb", "") - self.testcase(true, "Style in data-uri allowed", "default-src 'self'; style-src data: ", "linked_style_data.erb") - self.testcase(false, "Style in data-uri disallowed", "default-src 'self'; style-src 'self'", "linked_style_data.erb") + self.testcase(true, "Style in data-uri allowed", "default-src 'self'; style-src data: ", "linked_style_data.erb", { :include_host => true }) + self.testcase(false, "Style in data-uri disallowed", "default-src 'self'; style-src 'self'", "linked_style_data.erb", { :include_host => true }) self.testcase(true, "Use inline styles", "default-src 'self'; style-src 'self' 'unsafe-inline'", "inline_style.erb") self.testcase(false, "Use inline styles violation", "style-src 'self'", "inline_style.erb") self.testcase(true, "Use inline style attributes", "style-src 'self' 'unsafe-inline'", "inline_style_attr.erb") self.testcase(false, "Use inline style attributes violation", "style-src 'self'", "inline_style_attr.erb") self.create_testcases("script", "script-src", "linked_script.erb","") - self.testcase(true, "Script in data-uri allowed", "default-src 'self'; script-src data: ", "linked_script_data.erb") - self.testcase(false, "Script in data-uri disallowed", "default-src 'self'; script-src 'self'", "linked_script_data.erb") + self.testcase(true, "Script in data-uri allowed", "default-src 'self'; script-src data: ", "linked_script_data.erb", { :include_host => true }) + self.testcase(false, "Script in data-uri disallowed", "default-src 'self'; script-src 'self'", "linked_script_data.erb", { :include_host => true }) self.testcase(true, "Use inline script", "script-src 'unsafe-inline'", "inline_script_tag.erb") self.testcase(false, "Use inline script violation", "script-src 'self'", "inline_script_tag.erb") self.testcase(true, "Use inline script in event handler", "script-src 'unsafe-inline'", "inline_script_eventhandler.erb")