package markup import ( "strings" "testing" ) // Chapter 45.4's attacks, each a permanent test: no tag survives, though inert words may. func TestChapter45Attacks(t *testing.T) { cases := []struct { name, body string forbidden []string }{ {"script tag", ``, []string{" there`, []string{"\nb", []string{"
kept
`) if strings.Contains(got, "secret") { t.Errorf("the body of a script survived: %s", got) } if !strings.Contains(got, "kept") { t.Errorf("the text after it was lost: %s", got) } } // A tag never opened must not close, or a comment escapes its box into the page's layout. func TestUnbalancedTagsCannotEscape(t *testing.T) { got := Sanitize(`