@@ -86,7 +86,7 @@ void xssPrevented_heteroList_usingDescriptorDisplayName() throws Exception {
8686 assertThat (result , instanceOf (HTMLButtonElement .class ));
8787 HTMLButtonElement menuItem = (HTMLButtonElement ) result ;
8888 String menuItemContent = menuItem .getInnerHTML ();
89- assertThat (menuItemContent , not (containsString ("<" )));
89+ assertThat (menuItemContent , not (containsString ("<img " )));
9090 }
9191
9292 @ Test
@@ -100,7 +100,7 @@ void xssPrevented_usingToolInstallation_repeatableAddExisting() throws Exception
100100 Object result = page .executeJavaScript ("Array.from(document.querySelectorAll('button')).filter(b => b.textContent.indexOf('Add XSS') !== -1)[0].innerHTML" ).getJavaScriptResult ();
101101 assertThat (result , instanceOf (String .class ));
102102 String resultString = (String ) result ;
103- assertThat (resultString , not (containsString ("<" )));
103+ assertThat (resultString , not (containsString ("<img " )));
104104 }
105105
106106 // only possible after a partial fix
@@ -121,7 +121,7 @@ void xssPrevented_usingToolInstallation_repeatableAddAfterClick() throws Excepti
121121 Object result = page .executeJavaScript ("Array.from(document.querySelectorAll('button')).filter(b => b.textContent.indexOf('Add XSS') !== -1)[0].innerHTML" ).getJavaScriptResult ();
122122 assertThat (result , instanceOf (String .class ));
123123 String resultString = (String ) result ;
124- assertThat (resultString , not (containsString ("<" )));
124+ assertThat (resultString , not (containsString ("<img " )));
125125 }
126126
127127 @ Test
0 commit comments