1
0
mirror of https://github.com/django/django.git synced 2025-10-24 06:06:09 +00:00

Improved strip_tags and clarified documentation

The fact that strip_tags cannot guarantee to really strip all
non-safe HTML content was not clear enough. Also see:
https://www.djangoproject.com/weblog/2014/mar/22/strip-tags-advisory/
This commit is contained in:
Claude Paroz
2014-03-20 16:50:50 +01:00
parent aaa2110259
commit 6ca6c36f82
4 changed files with 51 additions and 10 deletions

View File

@@ -80,6 +80,8 @@ class TestUtilsHtml(TestCase):
('a<p a >b</p>c', 'abc'),
('d<a:b c:d>e</p>f', 'def'),
('<strong>foo</strong><a href="http://example.com">bar</a>', 'foobar'),
('<sc<!-- -->ript>test<<!-- -->/script>', 'test'),
('<script>alert()</script>&h', 'alert()&h'),
)
for value, output in items:
self.check_output(f, value, output)