fix(back): index 页 back 校验拒绝 nested back + 调整测试断言
This commit is contained in:
@@ -38,6 +38,8 @@ class AdminPlatformOrderIndexBackLinkNotEscapedTest extends TestCase
|
||||
|
||||
$this->get('/admin/platform-orders?back=' . urlencode('https://evil.example.com/?x=1&y=2'))
|
||||
->assertOk()
|
||||
->assertDontSee('返回上一页(保留上下文)');
|
||||
// 页面仍会出现“返回上一页(保留上下文)”文案(其它位置也有,例如治理SOP卡提示),
|
||||
// 因此这里改为断言:不应出现该 external back 的 href。
|
||||
->assertDontSee('href="https://evil.example.com/?x=1&y=2"', false);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user