47 lines
1.9 KiB
TypeScript
47 lines
1.9 KiB
TypeScript
import { describe, test, expect } from 'vitest';
|
|||
|
|
import { Icon } from './Icon';
|
||
|
|
|
||
|
|
const toHtml = (Icon as any).toHtml;
|
||
|
|
|
||
|
|
describe('Icon.toHtml normal rendering', () => {
|
||
|
|
test('renders icon class, size/color style, and link href', () => {
|
||
|
|
const { html } = toHtml({ icon: 'fa-star', size: '32px', color: '#3b82f6', link: 'https://example.com' }, '');
|
||
|
|
expect(html).toContain('class="fa fa-star"');
|
||
|
|
expect(html).toContain('font-size:32px');
|
||
|
|
expect(html).toContain('color:#3b82f6');
|
||
|
|
expect(html).toContain('href="https://example.com"');
|
||
|
|
});
|
||
|
|
});
|
||
|
|
|
||
|
|
describe('Icon.toHtml XSS hardening', () => {
|
||
|
|
test('an icon name with an attribute-breakout string is escaped, not raw-concatenated', () => {
|
||
|
|
const malicious = 'star"><script>alert(1)</script>';
|
||
|
|
const { html } = toHtml({ icon: malicious as any }, '');
|
||
|
|
expect(html).not.toContain('<script>alert(1)</script>');
|
||
|
|
expect(html).not.toMatch(/class="fa star"><script>/);
|
||
|
|
});
|
||
|
|
|
||
|
|
test('a size value with an attribute-breakout string cannot escape style=""', () => {
|
||
|
|
const malicious = '24px" onerror="alert(1)';
|
||
|
|
const { html } = toHtml({ size: malicious as any }, '');
|
||
|
|
expect(html).not.toMatch(/"\s+onerror="/);
|
||
|
|
});
|
||
|
|
|
||
|
|
test('a bgSize/bgColor breakout via background wrapper is neutralized', () => {
|
||
|
|
const malicious = '56px" onmouseover="alert(1)';
|
||
|
|
const { html } = toHtml({ bgShape: 'circle', bgColor: '#fff', bgSize: malicious as any }, '');
|
||
|
|
expect(html).not.toMatch(/"\s+onmouseover="/);
|
||
|
|
});
|
||
|
|
|
||
|
|
test('a javascript: link is neutralized to an empty href', () => {
|
||
|
|
const { html } = toHtml({ link: 'javascript:alert(1)' }, '');
|
||
|
|
expect(html).not.toContain('javascript:alert(1)');
|
||
|
|
});
|
||
|
|
|
||
|
|
test('a link value with an attribute-breakout string cannot escape href=""', () => {
|
||
|
|
const malicious = 'https://example.com" onclick="alert(1)';
|
||
|
|
const { html } = toHtml({ link: malicious as any }, '');
|
||
|
|
expect(html).not.toMatch(/"\s+onclick="/);
|
||
|
|
});
|
||
|
|
});
|