24 lines
988 B
TypeScript
24 lines
988 B
TypeScript
import { describe, test, expect } from 'vitest';
|
|||
|
|
import { FeaturesGrid } from './FeaturesGrid';
|
||
|
|
|
||
|
|
const toHtml = (FeaturesGrid as any).toHtml;
|
||
|
|
|
||
|
|
describe('FeaturesGrid.toHtml image sink uses safeImageUrl (data:image/svg+xml allowed)', () => {
|
||
|
|
test('feat.image as a data:image/svg+xml value emits a non-empty <img src>', () => {
|
||
|
|
const svgDataUri = 'data:image/svg+xml,%3Csvg%2F%3E';
|
||
|
|
const features = [
|
||
|
|
{ title: 'Feature', description: 'Desc', icon: '⚡', image: svgDataUri, imageAlt: 'alt' },
|
||
|
|
];
|
||
|
|
const { html } = toHtml({ features }, '');
|
||
|
|
expect(html).toContain(`<img src="${svgDataUri}"`);
|
||
|
|
});
|
||
|
|
|
||
|
|
test('feat.buttonUrl stays on safeUrl (data:image/svg+xml blocked as a navigation target)', () => {
|
||
|
|
const features = [
|
||
|
|
{ title: 'Feature', description: 'Desc', icon: '⚡', buttonText: 'Go', buttonUrl: 'data:image/svg+xml,<svg onload=alert(1)>' },
|
||
|
|
];
|
||
|
|
const { html } = toHtml({ features }, '');
|
||
|
|
expect(html).toMatch(/<a href=""/);
|
||
|
|
});
|
||
|
|
});
|