Secure your code as it's written. Use Snyk Code to scan source code in minutes - no build needed - and fix issues immediately.
it('prevents xss in path validation response message', (done) => {
const server = new Hapi.Server();
server.connection();
server.state('encoded', { encoding: 'iron' });
server.route({
method: 'GET', path: '/fail/{name}', handler: function (request, reply) {
return reply('Success');
},
config: {
validate: { params: { name: Joi.number() } }
}
});
server.inject({
method: 'GET',
url: '/fail/