|
|
var common = require('../common'); var test = require('utest'); var assert = common.assert; var IncomingForm = common.require('incoming_form').IncomingForm; var path = require('path');
var form; test('IncomingForm', { before: function() { form = new IncomingForm(); },
'#_fileName with regular characters': function() { var filename = 'foo.txt'; assert.equal(form._fileName(makeHeader(filename)), 'foo.txt'); },
'#_fileName with unescaped quote': function() { var filename = 'my".txt'; assert.equal(form._fileName(makeHeader(filename)), 'my".txt'); },
'#_fileName with escaped quote': function() { var filename = 'my%22.txt'; assert.equal(form._fileName(makeHeader(filename)), 'my".txt'); },
'#_fileName with bad quote and additional sub-header': function() { var filename = 'my".txt'; var header = makeHeader(filename) + '; foo="bar"'; assert.equal(form._fileName(header), filename); },
'#_fileName with semicolon': function() { var filename = 'my;.txt'; assert.equal(form._fileName(makeHeader(filename)), 'my;.txt'); },
'#_fileName with utf8 character': function() { var filename = 'my☃.txt'; assert.equal(form._fileName(makeHeader(filename)), 'my☃.txt'); },
'#_uploadPath strips harmful characters from extension when keepExtensions': function() { form.keepExtensions = true;
var ext = path.extname(form._uploadPath('fine.jpg?foo=bar')); assert.equal(ext, '.jpg');
var ext = path.extname(form._uploadPath('fine?foo=bar')); assert.equal(ext, '');
var ext = path.extname(form._uploadPath('super.cr2+dsad')); assert.equal(ext, '.cr2');
var ext = path.extname(form._uploadPath('super.bar')); assert.equal(ext, '.bar'); }, });
function makeHeader(filename) { return 'Content-Disposition: form-data; name="upload"; filename="' + filename + '"'; }
|