public void DRatingWithSqlMembers_WhenScrubbed_BecomesSafe() { //Arrange: An instruction with malicious html and sql members is constructed. string malicious = "1');DELETE TABLE dbo.example;--"; DRating instruction = new DRating{ Reasons = malicious }; //Act: The friended user is scrubbed. instruction.Scrub(); //Assert: The friended user has no html in its members. Assert.AreNotEqual(malicious, instruction.Reasons); }
public void DRatingWithHtmlMembers_WhenScrubbed_BecomesSafe() { //Arrange: An instruction with malicious sql members is constructed. string malicious = "<div></div>"; DRating instruction = new DRating{ Reasons = malicious }; //Act: The friended user is scrubbed. instruction.Scrub(); //Assert: The friended user has no html in its members. Assert.AreNotEqual(malicious, instruction.Reasons); }