2026-07-12 13:46:38 -07:00
|
|
|
import { describe, test, expect } from 'vitest';
|
|
|
|
|
import { Testimonials } from './Testimonials';
|
|
|
|
|
|
|
|
|
|
const toHtml = (Testimonials as any).toHtml;
|
|
|
|
|
|
|
|
|
|
const testimonials = [
|
|
|
|
|
{ quote: 'Quote one', name: 'Name One', title: 'Title One', rating: 5 },
|
|
|
|
|
{ quote: 'Quote two', name: 'Name Two', title: 'Title Two', rating: 4 },
|
|
|
|
|
{ quote: 'Quote three', name: 'Name Three', title: 'Title Three', rating: 3 },
|
|
|
|
|
];
|
|
|
|
|
|
|
|
|
|
describe('Testimonials.toHtml single-layout export parity', () => {
|
|
|
|
|
// The editor's "single" layout shows exactly one testimonial (a single
|
|
|
|
|
// card, no stacked list). Static-parity fix: toHtml exports exactly one
|
|
|
|
|
// card too (the first testimonial), matching what the editor displays by
|
|
|
|
|
// default -- not a stacked list of all testimonials, and not a JS carousel
|
|
|
|
|
// (this codebase's static export has no published-JS interactivity for
|
|
|
|
|
// this component).
|
|
|
|
|
test('single layout: exports exactly one testimonial card, not all of them', () => {
|
|
|
|
|
const { html } = toHtml({ testimonials, layout: 'single' }, '');
|
|
|
|
|
expect(html).toContain('Name One');
|
|
|
|
|
expect(html).not.toContain('Name Two');
|
|
|
|
|
expect(html).not.toContain('Name Three');
|
|
|
|
|
expect(html).toContain('Quote one');
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('single layout: no carousel controls (prev/next/dots) in static export', () => {
|
|
|
|
|
const { html } = toHtml({ testimonials, layout: 'single' }, '');
|
|
|
|
|
expect(html).not.toContain('fa-chevron-left');
|
|
|
|
|
expect(html).not.toContain('fa-chevron-right');
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('grid layout: still exports all testimonials (unchanged behavior)', () => {
|
|
|
|
|
const { html } = toHtml({ testimonials, layout: 'grid' }, '');
|
|
|
|
|
expect(html).toContain('Name One');
|
|
|
|
|
expect(html).toContain('Name Two');
|
|
|
|
|
expect(html).toContain('Name Three');
|
|
|
|
|
});
|
|
|
|
|
});
|
2026-07-12 14:19:01 -07:00
|
|
|
|
|
|
|
|
describe('Testimonials.toHtml decorative star icons (F2.5)', () => {
|
|
|
|
|
test('star glyphs are aria-hidden', () => {
|
|
|
|
|
const { html } = toHtml({ testimonials, layout: 'grid' }, '');
|
|
|
|
|
const stars = html.match(/<i class="fa fa-star[^"]*"[^>]*>/g) || [];
|
|
|
|
|
expect(stars.length).toBeGreaterThan(0);
|
|
|
|
|
stars.forEach((tag: string) => expect(tag).toContain('aria-hidden="true"'));
|
|
|
|
|
});
|
|
|
|
|
});
|
2026-07-12 18:03:44 -07:00
|
|
|
|
|
|
|
|
describe('Testimonials.toHtml rating aria-label sink (attacker-controlled `rating`, typed number but unchecked)', () => {
|
|
|
|
|
test('malicious rating value cannot break out of the star row aria-label attribute', () => {
|
|
|
|
|
const malicious = [
|
|
|
|
|
{ quote: 'Q', name: 'N', title: 'T', rating: '5"><script>alert(1)</script>' as any },
|
|
|
|
|
];
|
|
|
|
|
const { html } = toHtml({ testimonials: malicious, layout: 'grid' }, '');
|
|
|
|
|
expect(html).not.toContain('<script>alert(1)</script>');
|
|
|
|
|
expect(html).not.toContain('5"><script>');
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('non-numeric rating falls back to a safe numeric value', () => {
|
|
|
|
|
const malicious = [
|
|
|
|
|
{ quote: 'Q', name: 'N', title: 'T', rating: 'not-a-number' as any },
|
|
|
|
|
];
|
|
|
|
|
const { html } = toHtml({ testimonials: malicious, layout: 'grid' }, '');
|
|
|
|
|
expect(html).toMatch(/aria-label="Rating: 0 out of 5"/);
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
test('normal numeric rating still renders correctly', () => {
|
|
|
|
|
const { html } = toHtml({ testimonials, layout: 'grid' }, '');
|
|
|
|
|
expect(html).toContain('aria-label="Rating: 5 out of 5"');
|
|
|
|
|
expect(html).toContain('aria-label="Rating: 4 out of 5"');
|
|
|
|
|
});
|
|
|
|
|
});
|