for(Stringpath:newString[]{/* control */"scriptText",/* test */"scriptText/..;/cli"}){
try{
fail(path+" should have been rejected: "+r.createWebClient().login("admin").getPage(newWebRequest(newURL(r.getURL(),path+"?script=11*11"),HttpMethod.POST)).getWebResponse().getContentAsString());
}catch(FailingHttpStatusCodeExceptionx){
assertEquals("status code using "+path,403,x.getStatusCode());
assertThat("error message using "+path,x.getResponse().getContentAsString(),containsString("No valid crumb was included in the request"));