SuggestionsTest.php 1.46 KB
Newer Older
Ketan's avatar
Ketan committed
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46
<?php
/**
 * Copyright © Magento, Inc. All rights reserved.
 * See COPYING.txt for license details.
 */
namespace Magento\AdvancedSearch\Block;

use Magento\TestFramework\Helper\Bootstrap;
use Magento\Search\Model\QueryResult;
use Magento\AdvancedSearch\Model\SuggestedQueriesInterface;
use Magento\Framework\View\LayoutInterface;

/**
 * @magentoAppArea frontend
 */
class SuggestionsTest extends \PHPUnit\Framework\TestCase
{
    /** @var \Magento\AdvancedSearch\Block\Suggestions */
    protected $block;

    protected function setUp()
    {
        $suggestedQueries = $this->createMock(SuggestedQueriesInterface::CLASS);
        $suggestedQueries->expects($this->any())->method('getItems')->willReturn([
            new QueryResult('test item', 1),
            new QueryResult("<script>alert('Test');</script>", 1)
        ]);

        $this->block = Bootstrap::getObjectManager()->create(\Magento\AdvancedSearch\Block\Suggestions::class, [
            'searchDataProvider' => $suggestedQueries,
            'title' => 'title',
        ]);
    }

    public function testRenderEscaping()
    {
        $html = $this->block->toHtml();

        $this->assertContains('test+item', $html);
        $this->assertContains('test item', $html);

        $this->assertNotContains('<script>', $html);
        $this->assertContains('%3Cscript%3Ealert%28%27Test%27%29%3B%3C%2Fscript%3E', $html);
        $this->assertContains("&lt;script&gt;alert(&#039;Test&#039;);&lt;/script&gt;", $html);
    }
}