2026-07-12 18:03:44 -07:00
|
|
|
import { describe, test, expect } from 'vitest';
|
|
|
|
|
import { Icon } from './Icon';
|
|
|
|
|
|
|
|
|
|
const toHtml = (Icon as any).toHtml;
|
|
|
|
|
|
|
|
|
|
describe('Icon.toHtml normal rendering', () => {
|
|
|
|
|
test('renders icon class, size/color style, and link href', () => {
|
|
|
|
|
const { html } = toHtml({ icon: 'fa-star', size: '32px', color: '#3b82f6', link: 'https://example.com' }, '');
|
|
|
|
|
expect(html).toContain('class="fa fa-star"');
|
|
|
|
|
expect(html).toContain('font-size:32px');
|
|
|
|
|
expect(html).toContain('color:#3b82f6');
|
|
|
|
|
expect(html).toContain('href="https://example.com"');
|
|
|
|
|
});
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
describe('Icon.toHtml XSS hardening', () => {
|
|
|
|
|
test('an icon name with an attribute-breakout string is escaped, not raw-concatenated', () => {
|
|
|
|
|
const malicious = 'star"><script>alert(1)</script>';
|
|
|
|
|
const { html } = toHtml({ icon: malicious as any }, '');
|
|
|
|
|
expect(html).not.toContain('<script>alert(1)</script>');
|
|
|
|
|
expect(html).not.toMatch(/class="fa star"><script>/);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('a size value with an attribute-breakout string cannot escape style=""', () => {
|
|
|
|
|
const malicious = '24px" onerror="alert(1)';
|
|
|
|
|
const { html } = toHtml({ size: malicious as any }, '');
|
|
|
|
|
expect(html).not.toMatch(/"\s+onerror="/);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('a bgSize/bgColor breakout via background wrapper is neutralized', () => {
|
|
|
|
|
const malicious = '56px" onmouseover="alert(1)';
|
|
|
|
|
const { html } = toHtml({ bgShape: 'circle', bgColor: '#fff', bgSize: malicious as any }, '');
|
|
|
|
|
expect(html).not.toMatch(/"\s+onmouseover="/);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('a javascript: link is neutralized to an empty href', () => {
|
|
|
|
|
const { html } = toHtml({ link: 'javascript:alert(1)' }, '');
|
|
|
|
|
expect(html).not.toContain('javascript:alert(1)');
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('a link value with an attribute-breakout string cannot escape href=""', () => {
|
|
|
|
|
const malicious = 'https://example.com" onclick="alert(1)';
|
|
|
|
|
const { html } = toHtml({ link: malicious as any }, '');
|
|
|
|
|
expect(html).not.toMatch(/"\s+onclick="/);
|
|
|
|
|
});
|
|
|
|
|
});
|
2026-07-14 06:47:58 -07:00
|
|
|
|
|
|
|
|
describe('Icon.toHtml bgShape/bgColor/bgSize rendering (built but, until this panel update, unexposed)', () => {
|
|
|
|
|
test('bgShape="circle" + bgColor render a colored 50%-radius background box', () => {
|
|
|
|
|
const { html } = toHtml({ icon: 'fa-star', bgShape: 'circle', bgColor: '#3b82f6', bgSize: '64px' }, '');
|
|
|
|
|
expect(html).toContain('background-color:#3b82f6');
|
|
|
|
|
expect(html).toContain('border-radius:50%');
|
|
|
|
|
expect(html).toContain('width:64px');
|
|
|
|
|
expect(html).toContain('height:64px');
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('bgShape="none" (default) renders the bare icon with no background wrapper', () => {
|
|
|
|
|
const { html } = toHtml({ icon: 'fa-star' }, '');
|
|
|
|
|
expect(html).not.toContain('background-color');
|
|
|
|
|
});
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
describe('Icon.craft.props includes the box-model/animation/visibility rollout props', () => {
|
|
|
|
|
test('animation, animationDelay, and all 3 hideOn* flags are declared (blank/false defaults)', () => {
|
|
|
|
|
const props = (Icon as any).craft.props;
|
|
|
|
|
expect(props).toHaveProperty('animation', '');
|
|
|
|
|
expect(props).toHaveProperty('animationDelay', '');
|
|
|
|
|
expect(props).toHaveProperty('hideOnDesktop', false);
|
|
|
|
|
expect(props).toHaveProperty('hideOnTablet', false);
|
|
|
|
|
expect(props).toHaveProperty('hideOnMobile', false);
|
|
|
|
|
});
|
|
|
|
|
});
|