Skip to content

Commit

Permalink
[fix #12901] moved testSqlInjectionSearchAccountRequestsInWholeSystem…
Browse files Browse the repository at this point in the history
… to AccountRequestSearchIT class
  • Loading branch information
Ashwinn11 committed May 13, 2024
1 parent 06bfafd commit 2367769
Show file tree
Hide file tree
Showing 2 changed files with 17 additions and 15 deletions.
15 changes: 0 additions & 15 deletions src/it/java/teammates/it/storage/sqlapi/AccountRequestsDbIT.java
Original file line number Diff line number Diff line change
Expand Up @@ -237,19 +237,4 @@ public void testSqlInjectionInDeleteAccountRequest() throws Exception {
assertEquals(accountRequest, actual);
}

@Test
public void testSqlInjectionSearchAccountRequestsInWholeSystem() throws Exception {
______TS("SQL Injection test in searchAccountRequestsInWholeSystem");

AccountRequest accountRequest =
new AccountRequest("[email protected]", "name", "institute", AccountRequestStatus.PENDING, "comments");
accountRequestDb.createAccountRequest(accountRequest);

String searchInjection = "institute'; DROP TABLE account_requests; --";
List<AccountRequest> actualInjection = accountRequestDb.searchAccountRequestsInWholeSystem(searchInjection);
assertEquals(0, actualInjection.size());

AccountRequest actual = accountRequestDb.getAccountRequest(accountRequest.getId());
assertEquals(accountRequest, actual);
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@
import org.testng.annotations.BeforeMethod;
import org.testng.annotations.Test;

import teammates.common.datatransfer.AccountRequestStatus;
import teammates.common.datatransfer.SqlDataBundle;
import teammates.common.exception.SearchServiceException;
import teammates.common.util.HibernateUtil;
Expand Down Expand Up @@ -162,6 +163,22 @@ public void testSearchAccountRequest_noSearchService_shouldThrowException() {
() -> accountRequestsDb.searchAccountRequestsInWholeSystem("anything"));
}

@Test
public void testSqlInjectionSearchAccountRequestsInWholeSystem() throws Exception {
______TS("SQL Injection test in searchAccountRequestsInWholeSystem");

AccountRequest accountRequest =
new AccountRequest("[email protected]", "name", "institute", AccountRequestStatus.PENDING, "comments");
accountRequestsDb.createAccountRequest(accountRequest);

String searchInjection = "institute'; DROP TABLE account_requests; --";
List<AccountRequest> actualInjection = accountRequestsDb.searchAccountRequestsInWholeSystem(searchInjection);
assertEquals(0, actualInjection.size());

AccountRequest actual = accountRequestsDb.getAccountRequest(accountRequest.getId());
assertEquals(accountRequest, actual);
}

/**
* Verifies that search results match with expected output.
*
Expand Down

0 comments on commit 2367769

Please sign in to comment.