SecurityTest.php 2.01 KB
Newer Older
Ketan's avatar
Ketan committed
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81
<?php
/**
 * Copyright © Magento, Inc. All rights reserved.
 * See COPYING.txt for license details.
 */
namespace Magento\Framework\Xml\Test\Unit;

use Magento\Framework\Xml\Security;

/**
 * Class SecurityTest
 *
 * Test for class \Magento\Framework\Xml\Security
 */
class SecurityTest extends \PHPUnit\Framework\TestCase
{
    /**
     * @var Security
     */
    protected $security;

    /**
     * Set up
     *
     * @return void
     */
    protected function setUp()
    {
        $this->security = new Security();
    }

    /**
     * Run test scan method
     *
     * @param string $xmlContent
     * @param bool $expectedResult
     *
     * @dataProvider dataProviderTestScan
     */
    public function testScan($xmlContent, $expectedResult)
    {
        $this->assertEquals($expectedResult, $this->security->scan($xmlContent));
    }

    /**
     * Data provider for testScan
     *
     * @return array
     */
    public function dataProviderTestScan()
    {
        return [
            [
                'xmlContent' => '<?xml version="1.0"?><test></test>',
                'expectedResult' => true
            ],
            [
                'xmlContent' => '<!DOCTYPE note SYSTEM "Note.dtd"><?xml version="1.0"?><test></test>',
                'expectedResult' => false
            ],
            [
                'xmlContent' => '<?xml version="1.0"?>
            <!DOCTYPE test [
              <!ENTITY value "value">
              <!ENTITY value1 "&value;&value;&value;&value;&value;&value;&value;&value;&value;&value;">
              <!ENTITY value2 "&value1;&value1;&value1;&value1;&value1;&value1;&value1;&value1;&value1;&value1;">
            ]>
            <test>&value2;</test>',
                'expectedResult' => false
            ],
            [
                'xmlContent' => '<!DOCTYPE html><?xml version="1.0"?><test></test>',
                'expectedResult' => false
            ],
            [
                'xmlContent' => '',
                'expectedResult' => false
            ]
        ];
    }
}