public void DPlaceWithHtmlLongName_WhenScrubbed_BecomesSafe() { string malicious = "<div>Hello, world!</div>"; DPlace place = new DPlace { Long_Name = malicious }; place.Scrub(); Assert.AreNotEqual(place.Long_Name, malicious); }
public void DPlaceWithSqlShortName_WhenScrubbed_BecomesSafe() { string malicious = "<div>Hello, world!</div>');DROP TABLE dbo.Users;--"; DPlace place = new DPlace { Short_Name = malicious }; place.Scrub(); Assert.AreNotEqual(place.Short_Name, malicious); }
public void DPlaceWithHtmlAndSqlShortName_WhenScrubbed_BecomesSafe() { string malicious = "attribute');DROP TABLE dbo.Users;--"; DPlace place = new DPlace { Short_Name = malicious }; place.Scrub(); Assert.AreNotEqual(place.Short_Name, malicious); }