protected function XssTest::assertNotNormalized

Asserts that text transformed to lowercase with HTML entities decoded does not contain a given string.

Otherwise fails the test with a given message, similar to all the SimpleTest assert* functions.

Note that this does not remove nulls, new lines, and other character that could be used to obscure a tag or an attribute name.

Parameters

string $haystack: Text to look in.

string $needle: Lowercase, plain text to look for.

string $message: (optional) Message to display if failed. Defaults to an empty string.

string $group: (optional) The group this message belongs to. Defaults to 'Other'.

2 calls to XssTest::assertNotNormalized()
XssTest::testFilterXssAdminNotNormalized in drupal/core/tests/Drupal/Tests/Component/Utility/XssTest.php
Tests the loose, admin HTML filter.
XssTest::testFilterXssNotNormalized in drupal/core/tests/Drupal/Tests/Component/Utility/XssTest.php
Tests limiting allowed tags and XSS prevention.

File

drupal/core/tests/Drupal/Tests/Component/Utility/XssTest.php, line 563
Contains \Drupal\Tests\Component\Utility\XssTest.

Class

XssTest
Tests the Xss utility.

Namespace

Drupal\Tests\Component\Utility

Code

protected function assertNotNormalized($haystack, $needle, $message = '', $group = 'Other') {
  $this
    ->assertTrue(strpos(strtolower(String::decodeEntities($haystack)), $needle) === FALSE, $message, $group);
}