2026-07-12 14:19:01 -07:00
|
|
|
import { describe, test, expect } from 'vitest';
|
|
|
|
|
import { MapEmbed } from './MapEmbed';
|
|
|
|
|
|
|
|
|
|
const toHtml = (MapEmbed as any).toHtml;
|
|
|
|
|
|
|
|
|
|
describe('MapEmbed.toHtml iframe accessibility (F2.4)', () => {
|
|
|
|
|
test('iframe has a non-empty title attribute', () => {
|
|
|
|
|
const { html } = toHtml({ address: 'New York, NY' }, '');
|
|
|
|
|
expect(html).toMatch(/<iframe[^>]*title="[^"]+"/);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('title reflects the configured address', () => {
|
|
|
|
|
const { html } = toHtml({ address: 'Golden Gate Bridge' }, '');
|
|
|
|
|
expect(html).toContain('title="Map of Golden Gate Bridge"');
|
|
|
|
|
});
|
|
|
|
|
});
|
2026-07-12 14:35:27 -07:00
|
|
|
|
|
|
|
|
describe('MapEmbed.toHtml iframe src ampersand encoding (F-export review Minor)', () => {
|
|
|
|
|
test('the iframe src (built by string concatenation with literal &) emits & in the attribute, not a raw &', () => {
|
|
|
|
|
const { html } = toHtml({ address: 'New York, NY', zoom: 14 }, '');
|
|
|
|
|
const srcMatch = html.match(/<iframe src="([^"]+)"/);
|
|
|
|
|
expect(srcMatch).toBeTruthy();
|
|
|
|
|
// The raw src is `...q=...&z=14&output=embed` -- concatenated with
|
|
|
|
|
// literal `&`s -- so the emitted attribute must HTML-encode them.
|
|
|
|
|
expect(srcMatch![1]).toContain('&z=14');
|
|
|
|
|
expect(srcMatch![1]).toContain('&output=embed');
|
|
|
|
|
expect(srcMatch![1]).not.toMatch(/&(?!amp;)/);
|
|
|
|
|
});
|
|
|
|
|
});
|
2026-07-12 18:03:44 -07:00
|
|
|
|
|
|
|
|
describe('MapEmbed.toHtml address/zoom/height XSS hardening', () => {
|
|
|
|
|
test('a malicious address cannot break out of the src or title attribute', () => {
|
|
|
|
|
const malicious = 'X" onerror="alert(1)';
|
|
|
|
|
const { html } = toHtml({ address: malicious }, '');
|
|
|
|
|
expect(html).not.toContain('onerror="alert(1)"');
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('a wrong-typed zoom (string with attribute-breakout chars) cannot break out of the src attribute', () => {
|
|
|
|
|
const malicious = '14"><script>alert(1)</script>' as any;
|
|
|
|
|
const { html } = toHtml({ address: 'X', zoom: malicious }, '');
|
|
|
|
|
expect(html).not.toContain('<script>alert(1)</script>');
|
|
|
|
|
expect(html).not.toContain('"><script');
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('a wrong-typed zoom is coerced to a safe numeric value in the exported URL (defense in depth beyond escaping)', () => {
|
|
|
|
|
const malicious = '14"><script>alert(1)</script>' as any;
|
|
|
|
|
const { html } = toHtml({ address: 'X', zoom: malicious }, '');
|
|
|
|
|
const srcMatch = html.match(/<iframe src="([^"]+)"/);
|
|
|
|
|
expect(srcMatch).toBeTruthy();
|
|
|
|
|
// Decode the entity-escaped src back to a plain string and confirm the
|
|
|
|
|
// `z=` param is a bare, well-formed number -- not the raw attacker string.
|
|
|
|
|
const decoded = srcMatch![1].replace(/&/g, '&').replace(/"/g, '"').replace(/</g, '<').replace(/>/g, '>');
|
|
|
|
|
expect(decoded).toMatch(/[&?]z=\d+(&|$)/);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('a malicious height cannot break out of the iframe style attribute', () => {
|
|
|
|
|
const malicious = '400px" onmouseover="alert(1)';
|
|
|
|
|
const { html } = toHtml({ address: 'X', height: malicious }, '');
|
|
|
|
|
expect(html).not.toContain('onmouseover="alert(1)"');
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('a normal zoom/height still renders correctly', () => {
|
|
|
|
|
const { html } = toHtml({ address: 'X', zoom: 10, height: '300px' }, '');
|
|
|
|
|
expect(html).toContain('z=10');
|
|
|
|
|
expect(html).toContain('height:300px');
|
|
|
|
|
});
|
|
|
|
|
});
|