Skip to content

Commit

Permalink
wip
Browse files Browse the repository at this point in the history
  • Loading branch information
datlechin committed Jan 15, 2025
1 parent 8663ca6 commit 8ecf598
Showing 1 changed file with 3 additions and 3 deletions.
6 changes: 3 additions & 3 deletions tests/system/Security/SecurityTest.php
Original file line number Diff line number Diff line change
Expand Up @@ -359,12 +359,12 @@ public function testGetPostedTokenReturnsNullForInvalidInputs(): void
$method = $this->getPrivateMethodInvoker($this->createMockSecurity(), 'getPostedToken');
$testCases = [
'empty_post' => $this->createIncomingRequest(),
'malicious_post' => $this->createIncomingRequest()->setGlobal('post', ['csrf_test_name' => ['malicious' => 'data']]),
'invalid_post_data' => $this->createIncomingRequest()->setGlobal('post', ['csrf_test_name' => ['invalid' => 'data']]),
'empty_header' => $this->createIncomingRequest()->setHeader('X-CSRF-TOKEN', ''),
'malicious_json' => $this->createIncomingRequest()->setBody(json_encode(['csrf_test_name' => ['malicious' => 'data']])),
'invalid_json_data' => $this->createIncomingRequest()->setBody(json_encode(['csrf_test_name' => ['invalid' => 'data']])),
'invalid_json' => $this->createIncomingRequest()->setBody('{invalid json}'),
'missing_token_in_body' => $this->createIncomingRequest()->setBody('other=value&another=test'),
'malicious_form' => $this->createIncomingRequest()->setBody('csrf_test_name[]=malicious'),
'invalid_form_data' => $this->createIncomingRequest()->setBody('csrf_test_name[]=invalid'),
];

foreach ($testCases as $case => $request) {
Expand Down

0 comments on commit 8ecf598

Please sign in to comment.