Compare commits
17
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
72f85a97e5 | ||
|
|
ab28ad8f2c | ||
|
|
05e00c572d | ||
|
|
458069afb6 | ||
|
|
b3e5009aec | ||
|
|
eeb0660d83 | ||
|
|
138e1a8273 | ||
|
|
1b12b79a0d | ||
|
|
621bb21d52 | ||
|
|
3f3c6fb851 | ||
|
|
802938ec1a | ||
|
|
3e43aee6e9 | ||
|
|
bf4a9f48eb | ||
|
|
86455413d0 | ||
|
|
0cbc58f8d1 | ||
|
|
92841e3f35 | ||
|
|
e892ee0e53 |
+2
-1
@@ -1,6 +1,7 @@
|
||||
import React from 'react';
|
||||
import { Editor } from '@craftjs/core';
|
||||
import { EditorShell } from './editor/EditorShell';
|
||||
import { RenderNode } from './editor/RenderNode';
|
||||
import { componentResolver } from './components/resolver';
|
||||
import { WhpConfig } from './types';
|
||||
import { EditorConfigProvider } from './state/EditorConfigContext';
|
||||
@@ -23,7 +24,7 @@ export const App: React.FC<AppProps> = ({ whpConfig }) => {
|
||||
return (
|
||||
<EditorConfigProvider config={whpConfig}>
|
||||
<SiteDesignProvider>
|
||||
<Editor resolver={componentResolver} enabled={true}>
|
||||
<Editor resolver={componentResolver} enabled={true} onRender={RenderNode}>
|
||||
<PageProvider>
|
||||
<SitesmithProvider>
|
||||
<EditorShell />
|
||||
|
||||
@@ -21,3 +21,46 @@ describe('purifyHtml', () => {
|
||||
expect(purifyHtml('<form><input name="x"></form>')).not.toContain('<form');
|
||||
});
|
||||
});
|
||||
|
||||
describe('purifyHtml iframe sandboxing (M-6)', () => {
|
||||
test('forces a restrictive sandbox attribute onto every iframe', () => {
|
||||
const out = purifyHtml('<iframe src="https://example.com/"></iframe>');
|
||||
expect(out).toMatch(/<iframe[^>]*\bsandbox="[^"]+"/);
|
||||
});
|
||||
|
||||
test('sandbox value omits allow-top-navigation (no top-level nav escape)', () => {
|
||||
const out = purifyHtml('<iframe src="https://example.com/"></iframe>');
|
||||
const sandbox = out.match(/sandbox="([^"]*)"/)![1];
|
||||
expect(sandbox).not.toMatch(/allow-top-navigation/);
|
||||
});
|
||||
|
||||
test('legitimate embeds (YouTube) still work and get sandboxed too', () => {
|
||||
const out = purifyHtml('<iframe src="https://www.youtube.com/embed/abc" allowfullscreen></iframe>');
|
||||
expect(out).toContain('youtube.com/embed/abc');
|
||||
expect(out).toMatch(/<iframe[^>]*\bsandbox="[^"]+"/);
|
||||
});
|
||||
|
||||
test('adds referrerpolicy=no-referrer to iframes', () => {
|
||||
const out = purifyHtml('<iframe src="https://example.com/"></iframe>');
|
||||
expect(out).toContain('referrerpolicy="no-referrer"');
|
||||
});
|
||||
|
||||
test('script/on* attributes are still stripped alongside the sandboxed iframe', () => {
|
||||
const out = purifyHtml('<iframe src="https://example.com/" onload="alert(1)"></iframe><script>alert(2)</script>');
|
||||
expect(out).not.toContain('onload');
|
||||
expect(out).not.toContain('<script');
|
||||
});
|
||||
|
||||
test('repeated calls do not leak/accumulate the hook (no duplicate sandbox attr, no cross-call state)', () => {
|
||||
purifyHtml('<iframe src="https://a.example/"></iframe>');
|
||||
purifyHtml('<iframe src="https://b.example/"></iframe>');
|
||||
const out = purifyHtml('<iframe src="https://c.example/"></iframe>');
|
||||
const sandboxMatches = out.match(/sandbox="/g) || [];
|
||||
expect(sandboxMatches.length).toBe(1);
|
||||
});
|
||||
|
||||
test('a non-iframe element sanitized alongside an iframe is not touched by the hook', () => {
|
||||
const out = purifyHtml('<p>hi</p><iframe src="https://example.com/"></iframe>');
|
||||
expect(out).toContain('<p>hi</p>');
|
||||
});
|
||||
});
|
||||
|
||||
@@ -24,14 +24,42 @@ const PURIFY_CONFIG = {
|
||||
'href','src','alt','title','target','rel',
|
||||
'width','height','class',
|
||||
'allowfullscreen','allow','frameborder',
|
||||
'sandbox','referrerpolicy',
|
||||
],
|
||||
ALLOWED_URI_REGEXP: /^(?:(?:https?|mailto|tel|data:image\/[a-z]+;base64,):|[^a-z]|[a-z+.-]+(?:[^a-z+.\-:]|$))/i,
|
||||
FORBID_TAGS: ['script','style','object','embed','link','meta','form','input','button','select','textarea'],
|
||||
FORBID_ATTR: [/^on/i],
|
||||
};
|
||||
|
||||
// M-6: `<iframe>` is allowed (maps/video embeds are a legitimate use case)
|
||||
// but an iframe with a `src` and NO `sandbox` attribute is a clickjacking/
|
||||
// phishing vector (DOMPurify already strips <script>/on*=, but an
|
||||
// unsandboxed iframe still gets full script execution, same-origin-ish
|
||||
// access via document.domain tricks, top-level navigation, etc., inside
|
||||
// itself). This hook force-sets a restrictive sandbox on every iframe that
|
||||
// survives sanitization, keeping `allow-scripts`/`allow-same-origin`/
|
||||
// `allow-popups`/`allow-forms` (needed for interactive maps/video/oauth
|
||||
// popups) but deliberately omitting `allow-top-navigation` so an embedded
|
||||
// page can never redirect/hijack the parent tab.
|
||||
const IFRAME_SANDBOX_HOOK = (node: Element): void => {
|
||||
if (node.nodeName === 'IFRAME') {
|
||||
node.setAttribute('sandbox', 'allow-scripts allow-same-origin allow-popups allow-forms');
|
||||
node.setAttribute('referrerpolicy', 'no-referrer');
|
||||
}
|
||||
};
|
||||
|
||||
export function purifyHtml(input: string): string {
|
||||
// Hook is added immediately before sanitize() and removed immediately
|
||||
// after, scoped tightly to this single call -- so it can never leak onto
|
||||
// (or accumulate duplicate copies across) any other DOMPurify.sanitize()
|
||||
// call elsewhere in the app, and repeated purifyHtml() calls never stack
|
||||
// multiple copies of the same hook.
|
||||
DOMPurify.addHook('afterSanitizeAttributes', IFRAME_SANDBOX_HOOK);
|
||||
try {
|
||||
return DOMPurify.sanitize(input || '', PURIFY_CONFIG as any) as unknown as string;
|
||||
} finally {
|
||||
DOMPurify.removeHook('afterSanitizeAttributes', IFRAME_SANDBOX_HOOK as any);
|
||||
}
|
||||
}
|
||||
|
||||
export const HtmlBlock: UserComponent<HtmlBlockProps> = ({ code = '', style = {} }) => {
|
||||
|
||||
@@ -2,7 +2,7 @@ import React, { CSSProperties } from 'react';
|
||||
import { useNode, UserComponent } from '@craftjs/core';
|
||||
import { cssPropsToString } from '../../utils/style-helpers';
|
||||
import { useSiteDesign } from '../../state/SiteDesignContext';
|
||||
import { escapeHtml, escapeAttr, safeUrl } from '../../utils/escape';
|
||||
import { escapeHtml, escapeAttr, safeUrl, safeImageUrl } from '../../utils/escape';
|
||||
|
||||
/* ---------- Types ---------- */
|
||||
|
||||
@@ -104,7 +104,7 @@ Logo.craft = {
|
||||
let innerHtml: string;
|
||||
if (props.type === 'image' && props.imageSrc) {
|
||||
const imgStyle = cssPropsToString({ width: props.imageWidth || '120px', height: 'auto', display: 'block' });
|
||||
innerHtml = `<img src="${escapeAttr(safeUrl(props.imageSrc))}" alt="${escapeAttr(props.text || 'Logo')}"${imgStyle ? ` style="${imgStyle}"` : ''} />`;
|
||||
innerHtml = `<img src="${escapeAttr(safeImageUrl(props.imageSrc))}" alt="${escapeAttr(props.text || 'Logo')}"${imgStyle ? ` style="${imgStyle}"` : ''} />`;
|
||||
} else {
|
||||
const spanStyle = cssPropsToString({
|
||||
fontWeight: props.fontWeight || '700',
|
||||
|
||||
@@ -5,28 +5,84 @@ const toHtml = (Navbar as any).toHtml;
|
||||
|
||||
describe('Navbar.toHtml hamburger accessibility (F2.3)', () => {
|
||||
test('mobile toggle button has an accessible name, aria-expanded, and aria-controls', () => {
|
||||
const { html } = toHtml({ showMobileMenu: true }, '');
|
||||
const { html } = toHtml({ showMobileMenu: true }, '', 'node-nav1');
|
||||
expect(html).toMatch(/class="navbar-hamburger"[^>]*aria-label="Toggle navigation menu"/);
|
||||
expect(html).toMatch(/aria-expanded="false"/);
|
||||
expect(html).toMatch(/aria-controls="navbar-links"/);
|
||||
expect(html).toMatch(/aria-controls="[^"]+"/);
|
||||
});
|
||||
|
||||
test('aria-controls target id exists on the links container', () => {
|
||||
const { html } = toHtml({ showMobileMenu: true }, '');
|
||||
expect(html).toContain('id="navbar-links"');
|
||||
const { html } = toHtml({ showMobileMenu: true }, '', 'node-nav1');
|
||||
const controls = html.match(/aria-controls="([^"]+)"/)![1];
|
||||
expect(html).toContain(`id="${controls}"`);
|
||||
});
|
||||
|
||||
test('toggle script flips aria-expanded on click', () => {
|
||||
const { html } = toHtml({ showMobileMenu: true }, '');
|
||||
const { html } = toHtml({ showMobileMenu: true }, '', 'node-nav1');
|
||||
expect(html).toMatch(/setAttribute\(['"]aria-expanded['"]/);
|
||||
});
|
||||
|
||||
test('no mobile menu: no hamburger button emitted', () => {
|
||||
const { html } = toHtml({ showMobileMenu: false }, '');
|
||||
const { html } = toHtml({ showMobileMenu: false }, '', 'node-nav1');
|
||||
expect(html).not.toContain('navbar-hamburger');
|
||||
});
|
||||
});
|
||||
|
||||
describe('Navbar.toHtml node-scoped ids/hover styles (M-1: two navbars must not collide)', () => {
|
||||
test('no bare unscoped id="navbar-links" is emitted', () => {
|
||||
const { html } = toHtml({ showMobileMenu: true }, '', 'node-nav1');
|
||||
expect(html).not.toContain('id="navbar-links"');
|
||||
});
|
||||
|
||||
test('two different node ids produce different links-container ids', () => {
|
||||
const { html: html1 } = toHtml({ showMobileMenu: true }, '', 'node-nav1');
|
||||
const { html: html2 } = toHtml({ showMobileMenu: true }, '', 'node-nav2');
|
||||
const id1 = html1.match(/id="([^"]+)"/)![1];
|
||||
const id2 = html2.match(/id="([^"]+)"/)![1];
|
||||
expect(id1).not.toBe(id2);
|
||||
});
|
||||
|
||||
test('aria-controls always equals the actual links-container id', () => {
|
||||
const { html } = toHtml({ showMobileMenu: true }, '', 'node-nav1');
|
||||
const controls = html.match(/aria-controls="([^"]+)"/)![1];
|
||||
const linksId = html.match(/id="([^"]+)"/)![1];
|
||||
expect(controls).toBe(linksId);
|
||||
});
|
||||
|
||||
test('hover style selectors are scoped per-instance, not bare .navbar-link/.navbar-cta', () => {
|
||||
const { html } = toHtml({ hoverColor: '#ff0000' }, '', 'node-nav1');
|
||||
// A selector rule that STARTS the line with .navbar-link:hover (i.e. not
|
||||
// preceded by a per-instance ancestor class) would be the old, unscoped,
|
||||
// globally-colliding form.
|
||||
expect(html).not.toMatch(/^\s*\.navbar-link:hover/m);
|
||||
expect(html).not.toMatch(/^\s*\.navbar-cta:hover/m);
|
||||
// still present, just scoped under a per-instance ancestor class
|
||||
expect(html).toMatch(/\.navbar-link:hover/);
|
||||
expect(html).toMatch(/\.[\w-]+ \.navbar-link:hover/);
|
||||
});
|
||||
|
||||
test('two navbars with different hoverColor do not leak style onto each other (scoped selectors differ)', () => {
|
||||
const { html: html1 } = toHtml({ hoverColor: '#ff0000' }, '', 'node-nav1');
|
||||
const { html: html2 } = toHtml({ hoverColor: '#00ff00' }, '', 'node-nav2');
|
||||
const scope1 = html1.match(/<style>\s*\.([\w-]+)\s/)![1];
|
||||
const scope2 = html2.match(/<style>\s*\.([\w-]+)\s/)![1];
|
||||
expect(scope1).not.toBe(scope2);
|
||||
expect(html1).toContain(`.${scope1} .navbar-link:hover`);
|
||||
expect(html2).toContain(`.${scope2} .navbar-link:hover`);
|
||||
});
|
||||
|
||||
test('a normal single navbar still renders its hover style (visual output preserved)', () => {
|
||||
const { html } = toHtml({ hoverColor: '#ff0000' }, '', 'node-nav1');
|
||||
expect(html).toMatch(/:hover\s*\{\s*color:\s*#ff0000/);
|
||||
});
|
||||
|
||||
test('same node id -> identical output across calls (deterministic)', () => {
|
||||
const { html: html1 } = toHtml({ showMobileMenu: true }, '', 'node-nav1');
|
||||
const { html: html2 } = toHtml({ showMobileMenu: true }, '', 'node-nav1');
|
||||
expect(html1).toBe(html2);
|
||||
});
|
||||
});
|
||||
|
||||
describe('Navbar.toHtml XSS hardening (hoverColor/backgroundColor/ctaColor into <style>)', () => {
|
||||
test('a hoverColor value containing </style><script> is neutralized in the hover <style> block', () => {
|
||||
const malicious = '#fff}</style><script>alert(1)</script><style>{';
|
||||
|
||||
@@ -2,7 +2,7 @@ import React, { CSSProperties, useState } from 'react';
|
||||
import { useNode, UserComponent } from '@craftjs/core';
|
||||
import { cssPropsToString } from '../../utils/style-helpers';
|
||||
import { useSiteDesign } from '../../state/SiteDesignContext';
|
||||
import { escapeHtml, escapeAttr, safeUrl, cssValue } from '../../utils/escape';
|
||||
import { escapeHtml, escapeAttr, safeUrl, safeImageUrl, cssValue, scopeId } from '../../utils/escape';
|
||||
|
||||
/* ---------- Types ---------- */
|
||||
|
||||
@@ -210,7 +210,7 @@ Navbar.craft = {
|
||||
|
||||
/* ---------- HTML export ---------- */
|
||||
|
||||
(Navbar as any).toHtml = (props: NavbarProps, _childrenHtml: string) => {
|
||||
(Navbar as any).toHtml = (props: NavbarProps, _childrenHtml: string, nodeId?: string) => {
|
||||
// Sanitized once here -- these are raw string-interpolation sinks below
|
||||
// (hoverCol/bgColor go into a <style> block, the worst case: </style>
|
||||
// breakout -> arbitrary <script>), see task-cssxss-brief.md.
|
||||
@@ -224,6 +224,19 @@ Navbar.craft = {
|
||||
const sticky = props.isSticky;
|
||||
const mobile = props.showMobileMenu;
|
||||
const logoUrl = props.logoUrl || '/';
|
||||
const links0 = props.links || defaultLinks;
|
||||
|
||||
// M-1: deterministic AND unique per-instance scope, keyed on the Craft
|
||||
// node id. Two Navbars on the same page previously emitted an identical
|
||||
// fixed id="navbar-links" (invalid duplicate-id HTML, ambiguous
|
||||
// aria-controls target) and unscoped `.navbar-link:hover`/`.navbar-cta:hover`
|
||||
// rules in each instance's own <style> block -- since both blocks target
|
||||
// the SAME global selector, the later one in the DOM silently overrides
|
||||
// the earlier one's hover color/behavior for BOTH navbars. Scoping the
|
||||
// links-container id and adding a per-instance class on the <nav> root
|
||||
// (used to prefix the hover selectors) eliminates both collisions.
|
||||
const scope = scopeId(nodeId, JSON.stringify(links0) + alignment + pad, 'nav');
|
||||
const linksId = `${scope}_links`;
|
||||
|
||||
const navStyle = cssPropsToString({
|
||||
display: 'flex',
|
||||
@@ -239,7 +252,7 @@ Navbar.craft = {
|
||||
let logoHtml: string;
|
||||
if (props.logoType === 'image' && props.logoImage) {
|
||||
const imgStyle = cssPropsToString({ width: props.logoWidth || '120px', height: 'auto', display: 'block' });
|
||||
logoHtml = `<a href="${escapeAttr(safeUrl(logoUrl))}" style="text-decoration:none;display:flex;align-items:center;flex-shrink:0"><img src="${escapeAttr(safeUrl(props.logoImage))}" alt="${escapeAttr(props.logoText || 'Logo')}"${imgStyle ? ` style="${imgStyle}"` : ''} /></a>`;
|
||||
logoHtml = `<a href="${escapeAttr(safeUrl(logoUrl))}" style="text-decoration:none;display:flex;align-items:center;flex-shrink:0"><img src="${escapeAttr(safeImageUrl(props.logoImage))}" alt="${escapeAttr(props.logoText || 'Logo')}"${imgStyle ? ` style="${imgStyle}"` : ''} /></a>`;
|
||||
} else {
|
||||
const logoStyle = cssPropsToString({
|
||||
fontWeight: '700',
|
||||
@@ -272,21 +285,23 @@ Navbar.craft = {
|
||||
// via aria-expanded, kept in sync with the .navbar-open class by the
|
||||
// inline onclick handler.
|
||||
const hamburgerHtml = mobile
|
||||
? `\n <button class="navbar-hamburger" aria-label="Toggle navigation menu" aria-expanded="false" aria-controls="navbar-links" onclick="var m=this.parentElement.querySelector('.navbar-links');var open=m.classList.toggle('navbar-open');this.setAttribute('aria-expanded', open ? 'true' : 'false');" style="display:none;background:none;border:none;cursor:pointer;padding:4px;flex-direction:column;gap:4px">
|
||||
? `\n <button class="navbar-hamburger" aria-label="Toggle navigation menu" aria-expanded="false" aria-controls="${escapeAttr(linksId)}" onclick="var m=document.getElementById('${linksId}');var open=m.classList.toggle('navbar-open');this.setAttribute('aria-expanded', open ? 'true' : 'false');" style="display:none;background:none;border:none;cursor:pointer;padding:4px;flex-direction:column;gap:4px">
|
||||
<span style="display:block;width:24px;height:2px;background-color:${escapeAttr(textCol)}"></span>
|
||||
<span style="display:block;width:24px;height:2px;background-color:${escapeAttr(textCol)}"></span>
|
||||
<span style="display:block;width:24px;height:2px;background-color:${escapeAttr(textCol)}"></span>
|
||||
</button>`
|
||||
: '';
|
||||
|
||||
// Hover CSS
|
||||
// Hover CSS -- scoped under `.${scope}` (a class on the <nav> root, added
|
||||
// below) so it can only ever match THIS instance's links/CTA, never bleed
|
||||
// into or get overridden by another Navbar instance's rules.
|
||||
const hoverCss = `<style>
|
||||
.navbar-link:hover { color: ${hoverCol} !important; }
|
||||
.navbar-cta:hover { filter: brightness(1.1); }${mobile ? `
|
||||
.${scope} .navbar-link:hover { color: ${hoverCol} !important; }
|
||||
.${scope} .navbar-cta:hover { filter: brightness(1.1); }${mobile ? `
|
||||
@media (max-width: 768px) {
|
||||
.navbar-hamburger { display: flex !important; }
|
||||
.navbar-links { display: none !important; position: absolute; top: 100%; left: 0; right: 0; flex-direction: column !important; background-color: ${bgColor}; padding: 12px 24px; gap: 12px !important; box-shadow: 0 4px 12px rgba(0,0,0,0.1); }
|
||||
.navbar-links.navbar-open { display: flex !important; }
|
||||
.${scope} .navbar-hamburger { display: flex !important; }
|
||||
.${scope} .navbar-links { display: none !important; position: absolute; top: 100%; left: 0; right: 0; flex-direction: column !important; background-color: ${bgColor}; padding: 12px 24px; gap: 12px !important; box-shadow: 0 4px 12px rgba(0,0,0,0.1); }
|
||||
.${scope} .navbar-links.navbar-open { display: flex !important; }
|
||||
}` : ''}
|
||||
</style>`;
|
||||
|
||||
@@ -309,9 +324,9 @@ Navbar.craft = {
|
||||
|
||||
return {
|
||||
html: `${hoverCss}
|
||||
<nav${navStyle ? ` style="${navStyle}${mobile ? ';position:relative' : ''}"` : ''}>
|
||||
<nav class="${scope}"${navStyle ? ` style="${navStyle}${mobile ? ';position:relative' : ''}"` : ''}>
|
||||
${logoHtml}${hamburgerHtml}
|
||||
<div class="navbar-links" id="navbar-links" style="display:flex;align-items:center;gap:24px">
|
||||
<div class="navbar-links" id="${linksId}" style="display:flex;align-items:center;gap:24px">
|
||||
${linksHtmlWithClass}
|
||||
</div>
|
||||
</nav>`,
|
||||
|
||||
@@ -0,0 +1,62 @@
|
||||
import { describe, test, expect, vi, beforeEach } from 'vitest';
|
||||
import React from 'react';
|
||||
import { createRoot, Root } from 'react-dom/client';
|
||||
import { act } from 'react-dom/test-utils';
|
||||
|
||||
/* ImageBlock only needs useNode from @craftjs/core. Mock it following the
|
||||
DOM-harness pattern in src/components/basic/Footer.editguard.test.tsx (no
|
||||
@testing-library/react in this repo) so we can render the real component
|
||||
tree and inspect the emitted <img src> without a real <Editor>. */
|
||||
vi.mock('@craftjs/core', () => ({
|
||||
useNode: (collect?: (node: any) => any) => {
|
||||
const node = { events: { selected: false } };
|
||||
return {
|
||||
connectors: { connect: (el: any) => el, drag: (el: any) => el },
|
||||
actions: { setProp: vi.fn() },
|
||||
...(collect ? collect(node) : {}),
|
||||
};
|
||||
},
|
||||
}));
|
||||
|
||||
import { ImageBlock } from './ImageBlock';
|
||||
|
||||
let container: HTMLDivElement;
|
||||
let root: Root;
|
||||
|
||||
function render(ui: React.ReactElement) {
|
||||
container = document.createElement('div');
|
||||
document.body.appendChild(container);
|
||||
act(() => {
|
||||
root = createRoot(container);
|
||||
root.render(ui);
|
||||
});
|
||||
}
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
});
|
||||
|
||||
describe('ImageBlock render falls back to the placeholder for an explicit empty src (Bug 1)', () => {
|
||||
test('src="" (explicit, overrides the default parameter) still renders a non-empty placeholder src', () => {
|
||||
render(<ImageBlock src="" alt="Image" />);
|
||||
const img = container.querySelector('img')!;
|
||||
expect(img.getAttribute('src')).not.toBe('');
|
||||
expect(img.getAttribute('src')).toMatch(/^data:image\/svg\+xml/);
|
||||
container.remove();
|
||||
});
|
||||
|
||||
test('src=undefined (default parameter path) still renders the placeholder (unchanged behavior)', () => {
|
||||
render(<ImageBlock alt="Image" />);
|
||||
const img = container.querySelector('img')!;
|
||||
expect(img.getAttribute('src')).not.toBe('');
|
||||
expect(img.getAttribute('src')).toMatch(/^data:image\/svg\+xml/);
|
||||
container.remove();
|
||||
});
|
||||
|
||||
test('a real src is rendered unchanged', () => {
|
||||
render(<ImageBlock src="https://example.com/photo.jpg" alt="A photo" />);
|
||||
const img = container.querySelector('img')!;
|
||||
expect(img.getAttribute('src')).toBe('https://example.com/photo.jpg');
|
||||
container.remove();
|
||||
});
|
||||
});
|
||||
@@ -1,9 +1,9 @@
|
||||
import React, { CSSProperties, useCallback, useRef } from 'react';
|
||||
import { useNode, UserComponent } from '@craftjs/core';
|
||||
import { cssPropsToString } from '../../utils/style-helpers';
|
||||
import { escapeAttr, safeUrl } from '../../utils/escape';
|
||||
import { escapeAttr, safeImageUrl } from '../../utils/escape';
|
||||
|
||||
const PLACEHOLDER_SRC = "data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' width='400' height='300'%3E%3Cdefs%3E%3ClinearGradient id='bg' x1='0' y1='0' x2='0' y2='1'%3E%3Cstop offset='0%25' stop-color='%23f1f5f9'/%3E%3Cstop offset='100%25' stop-color='%23e2e8f0'/%3E%3C/linearGradient%3E%3C/defs%3E%3Crect fill='url(%23bg)' width='400' height='300' rx='12'/%3E%3Crect x='2' y='2' width='396' height='296' rx='10' fill='none' stroke='%23cbd5e1' stroke-width='2' stroke-dasharray='8 4'/%3E%3Cg transform='translate(200,110)'%3E%3Crect x='-28' y='-28' width='56' height='56' rx='12' fill='%23cbd5e1' opacity='0.5'/%3E%3Cpath d='M-12 8 L-4 -2 L2 4 L8 -6 L16 8Z' fill='%2394a3b8'/%3E%3Ccircle cx='-6' cy='-10' r='5' fill='%2394a3b8'/%3E%3C/g%3E%3Ctext x='200' y='160' text-anchor='middle' fill='%2364748b' font-family='Inter,sans-serif' font-size='15' font-weight='500'%3EDrop image here%3C/text%3E%3Ctext x='200' y='182' text-anchor='middle' fill='%2394a3b8' font-family='Inter,sans-serif' font-size='12'%3Eor click to upload%3C/text%3E%3C/svg%3E";
|
||||
export const PLACEHOLDER_SRC = "data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' width='400' height='300'%3E%3Cdefs%3E%3ClinearGradient id='bg' x1='0' y1='0' x2='0' y2='1'%3E%3Cstop offset='0%25' stop-color='%23f1f5f9'/%3E%3Cstop offset='100%25' stop-color='%23e2e8f0'/%3E%3C/linearGradient%3E%3C/defs%3E%3Crect fill='url(%23bg)' width='400' height='300' rx='12'/%3E%3Crect x='2' y='2' width='396' height='296' rx='10' fill='none' stroke='%23cbd5e1' stroke-width='2' stroke-dasharray='8 4'/%3E%3Cg transform='translate(200,110)'%3E%3Crect x='-28' y='-28' width='56' height='56' rx='12' fill='%23cbd5e1' opacity='0.5'/%3E%3Cpath d='M-12 8 L-4 -2 L2 4 L8 -6 L16 8Z' fill='%2394a3b8'/%3E%3Ccircle cx='-6' cy='-10' r='5' fill='%2394a3b8'/%3E%3C/g%3E%3Ctext x='200' y='160' text-anchor='middle' fill='%2364748b' font-family='Inter,sans-serif' font-size='15' font-weight='500'%3EDrop image here%3C/text%3E%3Ctext x='200' y='182' text-anchor='middle' fill='%2394a3b8' font-family='Inter,sans-serif' font-size='12'%3Eor click to upload%3C/text%3E%3C/svg%3E";
|
||||
|
||||
interface ImageBlockProps {
|
||||
src?: string;
|
||||
@@ -66,7 +66,7 @@ export const ImageBlock: UserComponent<ImageBlockProps> = ({
|
||||
imgRef.current = ref;
|
||||
if (ref) connect(drag(ref));
|
||||
}}
|
||||
src={src}
|
||||
src={src || PLACEHOLDER_SRC}
|
||||
alt={alt || 'Image'}
|
||||
onDrop={handleDrop}
|
||||
onDragOver={handleDragOver}
|
||||
@@ -95,5 +95,5 @@ ImageBlock.craft = {
|
||||
}
|
||||
const s = cssPropsToString({ display: 'block', maxWidth: '100%', ...props.style });
|
||||
const alt = props.alt ? ` alt="${escapeAttr(props.alt)}"` : ' alt=""';
|
||||
return { html: `<img src="${escapeAttr(safeUrl(src))}"${alt}${s ? ` style="${s}"` : ''} />` };
|
||||
return { html: `<img src="${escapeAttr(safeImageUrl(src))}"${alt}${s ? ` style="${s}"` : ''} />` };
|
||||
};
|
||||
|
||||
@@ -109,6 +109,15 @@ describe('ContentSlider.toHtml renders slide.imageSrc as a background-image (INT
|
||||
expect(html).not.toContain('background-image:url(');
|
||||
expect(html).toContain('background-color:#123456');
|
||||
});
|
||||
|
||||
test('a slide with a data:image/svg+xml imageSrc exports a non-empty background-image url (safeImageUrl, not safeUrl)', () => {
|
||||
const svgDataUri = 'data:image/svg+xml,%3Csvg%2F%3E';
|
||||
const slidesWithSvg = [
|
||||
{ type: 'image' as const, imageSrc: svgDataUri, heading: 'One' },
|
||||
];
|
||||
const { html } = toHtml({ slides: slidesWithSvg }, '');
|
||||
expect(html).toContain(`background-image:url('${svgDataUri}')`);
|
||||
});
|
||||
});
|
||||
|
||||
describe('ContentSlider.toHtml interval is NOT runtime-type-checked -- must be coerced before it reaches the inline <script> numeric context', () => {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
import React, { CSSProperties, useState, useEffect, useRef, useCallback } from 'react';
|
||||
import { useNode, UserComponent } from '@craftjs/core';
|
||||
import { cssPropsToString } from '../../utils/style-helpers';
|
||||
import { escapeHtml, escapeAttr, safeUrl, scopeId, cssValue } from '../../utils/escape';
|
||||
import { escapeHtml, escapeAttr, safeUrl, safeImageUrl, scopeId, cssValue } from '../../utils/escape';
|
||||
|
||||
interface Slide {
|
||||
type: 'image' | 'content';
|
||||
@@ -283,7 +283,7 @@ ContentSlider.craft = {
|
||||
// sink (a malicious value could break out of the style="..." attribute).
|
||||
const safeBgColor = cssValue(slide.bgColor) || '#3b82f6';
|
||||
const bgStyle = hasBgImage
|
||||
? `background-image:url('${escapeAttr(safeUrl(slide.imageSrc!))}');background-size:cover;background-position:center`
|
||||
? `background-image:url('${escapeAttr(safeImageUrl(slide.imageSrc!))}');background-size:cover;background-position:center`
|
||||
: slide.bgColor?.startsWith('linear-gradient')
|
||||
? `background-image:${safeBgColor}`
|
||||
: `background-color:${safeBgColor}`;
|
||||
|
||||
@@ -0,0 +1,23 @@
|
||||
import { describe, test, expect } from 'vitest';
|
||||
import { FeaturesGrid } from './FeaturesGrid';
|
||||
|
||||
const toHtml = (FeaturesGrid as any).toHtml;
|
||||
|
||||
describe('FeaturesGrid.toHtml image sink uses safeImageUrl (data:image/svg+xml allowed)', () => {
|
||||
test('feat.image as a data:image/svg+xml value emits a non-empty <img src>', () => {
|
||||
const svgDataUri = 'data:image/svg+xml,%3Csvg%2F%3E';
|
||||
const features = [
|
||||
{ title: 'Feature', description: 'Desc', icon: '⚡', image: svgDataUri, imageAlt: 'alt' },
|
||||
];
|
||||
const { html } = toHtml({ features }, '');
|
||||
expect(html).toContain(`<img src="${svgDataUri}"`);
|
||||
});
|
||||
|
||||
test('feat.buttonUrl stays on safeUrl (data:image/svg+xml blocked as a navigation target)', () => {
|
||||
const features = [
|
||||
{ title: 'Feature', description: 'Desc', icon: '⚡', buttonText: 'Go', buttonUrl: 'data:image/svg+xml,<svg onload=alert(1)>' },
|
||||
];
|
||||
const { html } = toHtml({ features }, '');
|
||||
expect(html).toMatch(/<a href=""/);
|
||||
});
|
||||
});
|
||||
@@ -1,7 +1,7 @@
|
||||
import React, { CSSProperties } from 'react';
|
||||
import { useNode, UserComponent } from '@craftjs/core';
|
||||
import { cssPropsToString } from '../../utils/style-helpers';
|
||||
import { escapeHtml, escapeAttr, safeUrl } from '../../utils/escape';
|
||||
import { escapeHtml, escapeAttr, safeUrl, safeImageUrl } from '../../utils/escape';
|
||||
|
||||
interface FeatureItem {
|
||||
title: string;
|
||||
@@ -116,7 +116,7 @@ FeaturesGrid.craft = {
|
||||
const idAttr = props.anchorId ? ` id="${escapeAttr(props.anchorId)}"` : '';
|
||||
const cards = (props.features || defaultFeatures).map((feat) => {
|
||||
const media = feat.image
|
||||
? `<img src="${escapeAttr(safeUrl(feat.image))}" alt="${escapeAttr(feat.imageAlt || feat.title || '')}" style="max-width:100%;height:auto;margin-bottom:16px;border-radius:8px">`
|
||||
? `<img src="${escapeAttr(safeImageUrl(feat.image))}" alt="${escapeAttr(feat.imageAlt || feat.title || '')}" style="max-width:100%;height:auto;margin-bottom:16px;border-radius:8px">`
|
||||
: `<div style="font-size:36px;margin-bottom:16px">${escapeHtml(feat.icon)}</div>`;
|
||||
const button = feat.buttonText
|
||||
? `\n <a href="${escapeAttr(safeUrl(feat.buttonUrl || '#'))}" style="display:inline-block;margin-top:16px;padding:10px 24px;background:#3b82f6;color:#fff;border-radius:8px;text-decoration:none;font-size:14px;font-weight:600">${escapeHtml(feat.buttonText)}</a>`
|
||||
|
||||
@@ -93,3 +93,59 @@ describe('Gallery.toHtml deterministic + unique scope ids (thread node id, no Ma
|
||||
expect(html1).toBe(html2);
|
||||
});
|
||||
});
|
||||
|
||||
describe('Gallery.toHtml default SVG placeholder images survive export (Bug 2 regression)', () => {
|
||||
test('a default data:image/svg+xml image emits a non-empty img src, not src=""', () => {
|
||||
const { html } = toHtml({}, ''); // no images prop -> component default SVG placeholders
|
||||
expect(html).not.toContain('src=""');
|
||||
expect(html).toMatch(/src="data:image\/svg\+xml[^"]*"/);
|
||||
});
|
||||
|
||||
test('an explicit data:image/svg+xml gallery image src is preserved (not stripped to empty)', () => {
|
||||
const svg = 'data:image/svg+xml,%3Csvg%2F%3E';
|
||||
const { html } = toHtml({ images: [{ src: svg, alt: 'a' }] }, '');
|
||||
expect(html).toContain(`src="${svg}"`);
|
||||
});
|
||||
|
||||
test('lightbox data-lb-src also preserves data:image/svg+xml (still an image context)', () => {
|
||||
const svg = 'data:image/svg+xml,%3Csvg%2F%3E';
|
||||
const { html } = toHtml({ images: [{ src: svg, alt: 'a' }], lightbox: true }, '');
|
||||
expect(html).toContain(`data-lb-src="${svg}"`);
|
||||
});
|
||||
|
||||
test('a javascript: gallery image src still yields an empty src (safeImageUrl still blocks it)', () => {
|
||||
const { html } = toHtml({ images: [{ src: 'javascript:alert(1)', alt: 'a' }] }, '');
|
||||
expect(html).toContain('src=""');
|
||||
expect(html).not.toContain('javascript:');
|
||||
});
|
||||
});
|
||||
|
||||
describe('Gallery.toHtml lightbox focus management (M-2)', () => {
|
||||
const props = { images: [{ src: '/a.jpg', alt: 'a' }], lightbox: true };
|
||||
|
||||
test('overlay includes a focusable close control with an accessible name and tabindex', () => {
|
||||
const { html } = toHtml(props, '', 'node-gal1');
|
||||
// A close control: a button (or the dialog container) with an accessible
|
||||
// name (aria-label) and an explicit tabindex so it's keyboard-focusable.
|
||||
expect(html).toMatch(/aria-label="[^"]*[Cc]lose[^"]*"[^>]*tabindex="-?\d+"|tabindex="-?\d+"[^>]*aria-label="[^"]*[Cc]lose[^"]*"/);
|
||||
});
|
||||
|
||||
test('script saves document.activeElement on open (for focus restore)', () => {
|
||||
const { html } = toHtml(props, '', 'node-gal1');
|
||||
expect(html).toMatch(/document\.activeElement/);
|
||||
});
|
||||
|
||||
test('script moves focus to the close control / dialog on open', () => {
|
||||
const { html } = toHtml(props, '', 'node-gal1');
|
||||
expect(html).toMatch(/\.focus\(\)/);
|
||||
});
|
||||
|
||||
test('script restores the previously-saved focus on close', () => {
|
||||
const { html } = toHtml(props, '', 'node-gal1');
|
||||
// The close function references a stored "last focused element" variable
|
||||
// and calls .focus() on it, not just moving focus INTO the dialog.
|
||||
const closeFnMatch = html.match(/function\s+\w+_close\s*\(\)\s*\{[^}]*\}/);
|
||||
expect(closeFnMatch).not.toBeNull();
|
||||
expect(closeFnMatch![0]).toMatch(/\.focus\(\)/);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
import React, { CSSProperties } from 'react';
|
||||
import { useNode, UserComponent } from '@craftjs/core';
|
||||
import { cssPropsToString } from '../../utils/style-helpers';
|
||||
import { escapeHtml, escapeAttr, safeUrl, scopeId, cssValue } from '../../utils/escape';
|
||||
import { escapeHtml, escapeAttr, safeImageUrl, scopeId, cssValue } from '../../utils/escape';
|
||||
|
||||
interface GalleryImage {
|
||||
src: string;
|
||||
@@ -154,10 +154,10 @@ Gallery.craft = {
|
||||
// inline onclick with an interpolated src -- a single delegated click
|
||||
// listener below reads it, so a src containing a quote can't break out
|
||||
// of a per-item event-handler string.
|
||||
const lbAttr = lightbox ? ` data-lb-src="${escapeAttr(safeUrl(img.src || ''))}" role="button" tabindex="0"` : '';
|
||||
const lbAttr = lightbox ? ` data-lb-src="${escapeAttr(safeImageUrl(img.src || ''))}" role="button" tabindex="0"` : '';
|
||||
const itemStyle = lightbox ? 'cursor:pointer;position:relative;overflow:hidden;border-radius:8px' : 'position:relative;overflow:hidden;border-radius:8px';
|
||||
return `<div${lbAttr} style="${itemStyle}">
|
||||
<img src="${escapeAttr(safeUrl(img.src || ''))}" alt="${escapeAttr(img.alt)}" style="width:100%;height:200px;object-fit:cover;display:block;border-radius:8px;background-color:#f1f5f9" />
|
||||
<img src="${escapeAttr(safeImageUrl(img.src || ''))}" alt="${escapeAttr(img.alt)}" style="width:100%;height:200px;object-fit:cover;display:block;border-radius:8px;background-color:#f1f5f9" />
|
||||
${caption}
|
||||
</div>`;
|
||||
}).join('\n ');
|
||||
@@ -166,16 +166,37 @@ Gallery.craft = {
|
||||
let gridIdAttr = '';
|
||||
if (lightbox) {
|
||||
gridIdAttr = ` id="${galleryId}_grid"`;
|
||||
// M-2: focus management for the lightbox dialog.
|
||||
// - OPEN: stash `document.activeElement` (the thumbnail that triggered
|
||||
// the open) in a module-scoped var, then move focus onto the close
|
||||
// button -- so a screen-reader/keyboard user lands inside the dialog
|
||||
// instead of focus staying on (or silently falling back to <body>)
|
||||
// behind the now-visible overlay.
|
||||
// - Tab trap: while the overlay is open, every Tab keypress is
|
||||
// intercepted and refocuses the close button (the dialog's only
|
||||
// focusable control besides Escape/click-to-close), so focus can
|
||||
// never wander out into the page content hidden behind the overlay.
|
||||
// - CLOSE (Escape, backdrop click, or the close button): restore focus
|
||||
// to the element stashed on open.
|
||||
lightboxHtml = `
|
||||
<div id="${galleryId}_overlay" role="dialog" aria-modal="true" aria-label="Image preview" onclick="${galleryId}_close()" style="display:none;position:fixed;top:0;left:0;width:100%;height:100%;background:rgba(0,0,0,0.9);z-index:9999;justify-content:center;align-items:center;cursor:pointer">
|
||||
<button type="button" id="${galleryId}_closebtn" aria-label="Close preview" tabindex="-1" onclick="event.stopPropagation();${galleryId}_close()" style="position:absolute;top:16px;right:16px;width:36px;height:36px;border-radius:50%;border:none;background:rgba(255,255,255,0.15);color:#ffffff;font-size:20px;line-height:1;cursor:pointer;display:flex;align-items:center;justify-content:center">×</button>
|
||||
<img id="${galleryId}_img" src="" alt="" style="max-width:90%;max-height:90%;object-fit:contain;border-radius:8px" />
|
||||
</div>
|
||||
<script>
|
||||
function ${galleryId}_close(){document.getElementById('${galleryId}_overlay').style.display='none';}
|
||||
var ${galleryId}_lastFocus = null;
|
||||
function ${galleryId}_close(){
|
||||
document.getElementById('${galleryId}_overlay').style.display='none';
|
||||
if(${galleryId}_lastFocus && ${galleryId}_lastFocus.focus) ${galleryId}_lastFocus.focus();
|
||||
${galleryId}_lastFocus = null;
|
||||
}
|
||||
function ${galleryId}_open(src){
|
||||
${galleryId}_lastFocus = document.activeElement;
|
||||
var o = document.getElementById('${galleryId}_overlay');
|
||||
document.getElementById('${galleryId}_img').src = src;
|
||||
o.style.display = 'flex';
|
||||
var c = document.getElementById('${galleryId}_closebtn');
|
||||
if(c) c.focus();
|
||||
}
|
||||
document.getElementById('${galleryId}_grid').addEventListener('click', function(e){
|
||||
var t = e.target.closest('[data-lb-src]');
|
||||
@@ -190,7 +211,14 @@ document.getElementById('${galleryId}_grid').addEventListener('keydown', functio
|
||||
${galleryId}_open(t.getAttribute('data-lb-src'));
|
||||
});
|
||||
document.addEventListener('keydown', function(e){
|
||||
if(e.key==='Escape'){ ${galleryId}_close(); }
|
||||
var o = document.getElementById('${galleryId}_overlay');
|
||||
if(!o || o.style.display==='none') return;
|
||||
if(e.key==='Escape'){ ${galleryId}_close(); return; }
|
||||
if(e.key==='Tab'){
|
||||
e.preventDefault();
|
||||
var c = document.getElementById('${galleryId}_closebtn');
|
||||
if(c) c.focus();
|
||||
}
|
||||
});
|
||||
</script>`;
|
||||
}
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
import React, { useMemo, useRef, useEffect } from 'react';
|
||||
import { Frame, Element } from '@craftjs/core';
|
||||
import { Frame, Element, useEditor } from '@craftjs/core';
|
||||
import { Container } from '../components/layout/Container';
|
||||
import { usePages } from '../state/PageContext';
|
||||
import { DeviceMode } from '../types';
|
||||
@@ -93,6 +93,33 @@ const ZonePreview: React.FC<{ craftState: string | null; zone: 'header' | 'foote
|
||||
);
|
||||
};
|
||||
|
||||
/**
|
||||
* First-run hint shown over the canvas drop area once the current page's
|
||||
* root node exists and has no children yet. Hidden the instant something
|
||||
* is dropped in, and while a drag is in progress (so it never fights the
|
||||
* drop-target UI). `pointer-events: none` (see .empty-canvas-hint in
|
||||
* editor.css) keeps it from intercepting clicks/drops meant for the
|
||||
* underlying empty canvas.
|
||||
*/
|
||||
export const EmptyCanvasHint: React.FC = () => {
|
||||
const { isEmpty, isDragging } = useEditor((state) => {
|
||||
const root = state.nodes['ROOT'];
|
||||
return {
|
||||
isEmpty: !!root && root.data.nodes.length === 0,
|
||||
isDragging: state.events.dragged.size > 0,
|
||||
};
|
||||
});
|
||||
|
||||
if (!isEmpty || isDragging) return null;
|
||||
|
||||
return (
|
||||
<div className="empty-canvas-hint">
|
||||
<i className="fa fa-cubes" aria-hidden />
|
||||
<span>Drag blocks from the left panel, or pick a Template to start.</span>
|
||||
</div>
|
||||
);
|
||||
};
|
||||
|
||||
export const Canvas: React.FC<CanvasProps> = ({ device }) => {
|
||||
const width = DEVICE_WIDTHS[device];
|
||||
const { isEditingHeader, isEditingFooter, headerPage, footerPage } = usePages();
|
||||
@@ -140,6 +167,7 @@ export const Canvas: React.FC<CanvasProps> = ({ device }) => {
|
||||
<ZonePreview craftState={headerPage.craftState} zone="header" />
|
||||
)}
|
||||
|
||||
<div style={{ position: 'relative' }}>
|
||||
<Frame>
|
||||
<Element
|
||||
is={Container}
|
||||
@@ -148,6 +176,8 @@ export const Canvas: React.FC<CanvasProps> = ({ device }) => {
|
||||
style={frameStyle}
|
||||
/>
|
||||
</Frame>
|
||||
{isEditingRegularPage && <EmptyCanvasHint />}
|
||||
</div>
|
||||
|
||||
{isEditingRegularPage && (
|
||||
<ZonePreview craftState={footerPage.craftState} zone="footer" />
|
||||
|
||||
@@ -0,0 +1,67 @@
|
||||
import { describe, test, expect, vi, beforeEach } from 'vitest';
|
||||
import React from 'react';
|
||||
import { createRoot, Root } from 'react-dom/client';
|
||||
import { act } from 'react-dom/test-utils';
|
||||
|
||||
/* Same DOM-harness pattern as Footer.editguard.test.tsx: mock @craftjs/core's
|
||||
useEditor so we can drive editor state without a real <Editor> tree. */
|
||||
let mockNodes: Record<string, { data: { nodes: string[] } }> = {};
|
||||
let mockDraggedSize = 0;
|
||||
|
||||
vi.mock('@craftjs/core', () => ({
|
||||
useEditor: (collect: (state: any) => any) =>
|
||||
collect({
|
||||
nodes: mockNodes,
|
||||
events: { dragged: { size: mockDraggedSize } },
|
||||
}),
|
||||
}));
|
||||
|
||||
import { EmptyCanvasHint } from './Canvas';
|
||||
|
||||
let container: HTMLDivElement;
|
||||
let root: Root;
|
||||
|
||||
function render(ui: React.ReactElement) {
|
||||
container = document.createElement('div');
|
||||
document.body.appendChild(container);
|
||||
act(() => {
|
||||
root = createRoot(container);
|
||||
root.render(ui);
|
||||
});
|
||||
}
|
||||
|
||||
beforeEach(() => {
|
||||
mockNodes = {};
|
||||
mockDraggedSize = 0;
|
||||
});
|
||||
|
||||
describe('EmptyCanvasHint', () => {
|
||||
test('renders nothing before ROOT has mounted (no root node yet)', () => {
|
||||
render(<EmptyCanvasHint />);
|
||||
expect(container.querySelector('.empty-canvas-hint')).toBeNull();
|
||||
container.remove();
|
||||
});
|
||||
|
||||
test('renders the hint once ROOT exists with zero children', () => {
|
||||
mockNodes = { ROOT: { data: { nodes: [] } } };
|
||||
render(<EmptyCanvasHint />);
|
||||
expect(container.querySelector('.empty-canvas-hint')).not.toBeNull();
|
||||
expect(container.textContent).toContain('Drag blocks from the left panel');
|
||||
container.remove();
|
||||
});
|
||||
|
||||
test('hides once the page has content', () => {
|
||||
mockNodes = { ROOT: { data: { nodes: ['node-1'] } } };
|
||||
render(<EmptyCanvasHint />);
|
||||
expect(container.querySelector('.empty-canvas-hint')).toBeNull();
|
||||
container.remove();
|
||||
});
|
||||
|
||||
test('hides while a drag is in progress, even on an empty root', () => {
|
||||
mockNodes = { ROOT: { data: { nodes: [] } } };
|
||||
mockDraggedSize = 1;
|
||||
render(<EmptyCanvasHint />);
|
||||
expect(container.querySelector('.empty-canvas-hint')).toBeNull();
|
||||
container.remove();
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,108 @@
|
||||
import { describe, test, expect, vi, beforeEach } from 'vitest';
|
||||
import React from 'react';
|
||||
import { createRoot, Root } from 'react-dom/client';
|
||||
import { act } from 'react-dom/test-utils';
|
||||
|
||||
/* Same DOM-harness pattern as Footer.editguard.test.tsx: mock @craftjs/core
|
||||
so RenderNode (the <Editor onRender> override) can be driven without a
|
||||
real Editor tree. document.body doubles as the portal target, same as
|
||||
the component itself uses. */
|
||||
let mockNode: {
|
||||
id: string;
|
||||
selected: boolean;
|
||||
dom: HTMLElement | null;
|
||||
displayName: string;
|
||||
parent: string | null;
|
||||
};
|
||||
const selectNodeSpy = vi.fn();
|
||||
|
||||
vi.mock('@craftjs/core', () => ({
|
||||
useEditor: () => ({ actions: { selectNode: selectNodeSpy } }),
|
||||
useNode: (collect?: (node: any) => any) => {
|
||||
const node = {
|
||||
events: { selected: mockNode.selected },
|
||||
dom: mockNode.dom,
|
||||
data: { custom: {}, displayName: mockNode.displayName, parent: mockNode.parent },
|
||||
};
|
||||
return { id: mockNode.id, ...(collect ? collect(node) : {}) };
|
||||
},
|
||||
}));
|
||||
|
||||
import { RenderNode } from './RenderNode';
|
||||
|
||||
let container: HTMLDivElement;
|
||||
let root: Root;
|
||||
let nodeDom: HTMLElement;
|
||||
|
||||
function render(ui: React.ReactElement) {
|
||||
container = document.createElement('div');
|
||||
document.body.appendChild(container);
|
||||
act(() => {
|
||||
root = createRoot(container);
|
||||
root.render(ui);
|
||||
});
|
||||
}
|
||||
|
||||
beforeEach(() => {
|
||||
nodeDom = document.createElement('div');
|
||||
document.body.appendChild(nodeDom);
|
||||
mockNode = { id: 'node-1', selected: false, dom: nodeDom, displayName: 'Heading', parent: 'ROOT' };
|
||||
selectNodeSpy.mockClear();
|
||||
});
|
||||
|
||||
const rendered = <span data-testid="inner">hello</span>;
|
||||
|
||||
describe('RenderNode (Editor onRender override)', () => {
|
||||
test('passes render through untouched when not selected', () => {
|
||||
render(<RenderNode render={rendered} />);
|
||||
expect(container.querySelector('[data-testid="inner"]')).not.toBeNull();
|
||||
expect(document.querySelector('.component-indicator')).toBeNull();
|
||||
container.remove();
|
||||
nodeDom.remove();
|
||||
});
|
||||
|
||||
test('shows the badge with the displayName when selected', () => {
|
||||
mockNode.selected = true;
|
||||
render(<RenderNode render={rendered} />);
|
||||
const badge = document.querySelector('.component-indicator');
|
||||
expect(badge).not.toBeNull();
|
||||
expect(badge?.textContent).toContain('Heading');
|
||||
container.remove();
|
||||
nodeDom.remove();
|
||||
document.querySelector('.component-indicator')?.remove();
|
||||
});
|
||||
|
||||
test('never shows a badge for ROOT even if "selected"', () => {
|
||||
mockNode.selected = true;
|
||||
mockNode.id = 'ROOT';
|
||||
render(<RenderNode render={rendered} />);
|
||||
expect(document.querySelector('.component-indicator')).toBeNull();
|
||||
container.remove();
|
||||
nodeDom.remove();
|
||||
});
|
||||
|
||||
test('chevron click selects the parent node', () => {
|
||||
mockNode.selected = true;
|
||||
mockNode.parent = 'parent-42';
|
||||
render(<RenderNode render={rendered} />);
|
||||
const chevron = document.querySelector('.component-indicator-parent-btn') as HTMLElement;
|
||||
expect(chevron).not.toBeNull();
|
||||
act(() => {
|
||||
chevron.dispatchEvent(new MouseEvent('mousedown', { bubbles: true }));
|
||||
});
|
||||
expect(selectNodeSpy).toHaveBeenCalledWith('parent-42');
|
||||
container.remove();
|
||||
nodeDom.remove();
|
||||
document.querySelector('.component-indicator')?.remove();
|
||||
});
|
||||
|
||||
test('no chevron when there is no parent', () => {
|
||||
mockNode.selected = true;
|
||||
mockNode.parent = null;
|
||||
render(<RenderNode render={rendered} />);
|
||||
expect(document.querySelector('.component-indicator-parent-btn')).toBeNull();
|
||||
container.remove();
|
||||
nodeDom.remove();
|
||||
document.querySelector('.component-indicator')?.remove();
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,76 @@
|
||||
import React, { useCallback, useEffect, useRef } from 'react';
|
||||
import { createPortal } from 'react-dom';
|
||||
import { useEditor, useNode } from '@craftjs/core';
|
||||
|
||||
interface RenderNodeProps {
|
||||
render: React.ReactElement;
|
||||
}
|
||||
|
||||
/**
|
||||
* Craft.js `<Editor onRender>` override -- wraps every node's render output.
|
||||
* For the currently-selected node it portals a floating badge (component
|
||||
* displayName + a "select parent" chevron) positioned over the node's real
|
||||
* DOM element. Non-selected nodes (the overwhelming majority) and ROOT pass
|
||||
* straight through as a Fragment, so this never touches layout, never
|
||||
* appears in `toHtml` export (that walks the Craft node tree, not this
|
||||
* portal), and doesn't wrap every node in extra DOM.
|
||||
*/
|
||||
export const RenderNode: React.FC<RenderNodeProps> = ({ render }) => {
|
||||
const { actions } = useEditor();
|
||||
const { id, isSelected, dom, name, parent } = useNode((node) => ({
|
||||
isSelected: node.events.selected,
|
||||
dom: node.dom,
|
||||
name: (node.data.props?.aiName as string) || node.data.displayName,
|
||||
parent: node.data.parent,
|
||||
}));
|
||||
|
||||
const badgeRef = useRef<HTMLDivElement>(null);
|
||||
const active = isSelected && id !== 'ROOT' && !!dom;
|
||||
|
||||
const updatePosition = useCallback(() => {
|
||||
if (!dom || !badgeRef.current) return;
|
||||
const rect = dom.getBoundingClientRect();
|
||||
const badgeHeight = 22;
|
||||
badgeRef.current.style.left = `${Math.max(rect.left, 0)}px`;
|
||||
badgeRef.current.style.top = `${Math.max(rect.top - badgeHeight, 0)}px`;
|
||||
}, [dom]);
|
||||
|
||||
useEffect(() => {
|
||||
if (!active) return;
|
||||
updatePosition();
|
||||
window.addEventListener('resize', updatePosition);
|
||||
document.addEventListener('scroll', updatePosition, true);
|
||||
return () => {
|
||||
window.removeEventListener('resize', updatePosition);
|
||||
document.removeEventListener('scroll', updatePosition, true);
|
||||
};
|
||||
}, [active, updatePosition]);
|
||||
|
||||
if (!active) return <>{render}</>;
|
||||
|
||||
return (
|
||||
<>
|
||||
{render}
|
||||
{createPortal(
|
||||
<div ref={badgeRef} className="component-indicator" style={{ position: 'fixed' }}>
|
||||
<span>{name}</span>
|
||||
{parent && (
|
||||
<button
|
||||
type="button"
|
||||
className="component-indicator-parent-btn"
|
||||
title="Select parent"
|
||||
aria-label={`Select parent of ${name}`}
|
||||
onMouseDown={(e) => {
|
||||
e.stopPropagation();
|
||||
actions.selectNode(parent);
|
||||
}}
|
||||
>
|
||||
<i className="fa fa-chevron-up" aria-hidden />
|
||||
</button>
|
||||
)}
|
||||
</div>,
|
||||
document.body
|
||||
)}
|
||||
</>
|
||||
);
|
||||
};
|
||||
@@ -1,6 +1,7 @@
|
||||
import { describe, test, expect } from 'vitest';
|
||||
import { buildSavePayload } from './useWhpApi';
|
||||
import { PageData } from '../types';
|
||||
import { DEFAULT_SITE_DESIGN } from '../state/SiteDesignContext';
|
||||
|
||||
const pageA: PageData = { id: 'home', name: 'Home', slug: 'index', craftState: 'STORED_HOME' };
|
||||
const pageB: PageData = { id: 'page_2', name: 'About', slug: 'about', craftState: 'STORED_ABOUT' };
|
||||
@@ -19,6 +20,8 @@ describe('buildSavePayload', () => {
|
||||
activePageId: '__header__',
|
||||
isEditingHeader: true,
|
||||
isEditingFooter: false,
|
||||
headCode: DEFAULT_SITE_DESIGN.headCode,
|
||||
design: DEFAULT_SITE_DESIGN,
|
||||
});
|
||||
|
||||
// The fresh live canvas must be reflected in header_craft_state, not the stale stored one.
|
||||
@@ -52,6 +55,8 @@ describe('buildSavePayload', () => {
|
||||
activePageId: '__footer__',
|
||||
isEditingHeader: false,
|
||||
isEditingFooter: true,
|
||||
headCode: DEFAULT_SITE_DESIGN.headCode,
|
||||
design: DEFAULT_SITE_DESIGN,
|
||||
});
|
||||
|
||||
expect(payload.footer_craft_state).toBe('LIVE_FOOTER');
|
||||
@@ -75,6 +80,8 @@ describe('buildSavePayload', () => {
|
||||
activePageId: 'home',
|
||||
isEditingHeader: false,
|
||||
isEditingFooter: false,
|
||||
headCode: DEFAULT_SITE_DESIGN.headCode,
|
||||
design: DEFAULT_SITE_DESIGN,
|
||||
});
|
||||
|
||||
// Live canvas goes to the active page and top-level slots.
|
||||
@@ -105,6 +112,8 @@ describe('buildSavePayload', () => {
|
||||
activePageId: 'home',
|
||||
isEditingHeader: false,
|
||||
isEditingFooter: false,
|
||||
headCode: DEFAULT_SITE_DESIGN.headCode,
|
||||
design: DEFAULT_SITE_DESIGN,
|
||||
});
|
||||
|
||||
// The live edit must land in pages_craft_state[0] (index.html slot),
|
||||
@@ -116,4 +125,26 @@ describe('buildSavePayload', () => {
|
||||
// The other page is untouched.
|
||||
expect(payload.pages_craft_state.find((p) => p.id === 'p2')?.craftState).toBe('STORED_ABOUT_2');
|
||||
});
|
||||
|
||||
test('head code + design tokens are included in the save payload', () => {
|
||||
const design = { ...DEFAULT_SITE_DESIGN, headCode: '<meta name="x">' };
|
||||
|
||||
const payload = buildSavePayload({
|
||||
siteId: 1,
|
||||
siteName: 'Test Site',
|
||||
liveCraftState: 'LIVE_PAGE_HOME',
|
||||
pages: [pageA, pageB],
|
||||
headerPage,
|
||||
footerPage,
|
||||
activePageId: 'home',
|
||||
isEditingHeader: false,
|
||||
isEditingFooter: false,
|
||||
headCode: '<meta name="x">',
|
||||
design,
|
||||
});
|
||||
|
||||
expect(payload.head_code).toBe('<meta name="x">');
|
||||
expect(payload.design).toEqual(design);
|
||||
expect(payload.design.headCode).toBe('<meta name="x">');
|
||||
});
|
||||
});
|
||||
|
||||
@@ -2,6 +2,7 @@ import { useCallback } from 'react';
|
||||
import { useEditor } from '@craftjs/core';
|
||||
import { useEditorConfig } from '../state/EditorConfigContext';
|
||||
import { usePages } from '../state/PageContext';
|
||||
import { useSiteDesign, SiteDesign } from '../state/SiteDesignContext';
|
||||
import { exportBodyHtml } from '../utils/html-export';
|
||||
import { PageData } from '../types';
|
||||
|
||||
@@ -18,6 +19,10 @@ export interface BuildSavePayloadInput {
|
||||
isEditingHeader: boolean;
|
||||
/** True when the live canvas is showing the footer zone (activePageId === '__footer__'). */
|
||||
isEditingFooter: boolean;
|
||||
/** Site-wide custom `<head>` code (also present on `design.headCode`). */
|
||||
headCode: string;
|
||||
/** Full site design tokens object -- lets load() restore colors/fonts/headCode. */
|
||||
design: SiteDesign;
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -45,6 +50,8 @@ export function buildSavePayload(input: BuildSavePayloadInput) {
|
||||
activePageId,
|
||||
isEditingHeader,
|
||||
isEditingFooter,
|
||||
headCode,
|
||||
design,
|
||||
} = input;
|
||||
|
||||
const isPageActive = !isEditingHeader && !isEditingFooter;
|
||||
@@ -173,6 +180,8 @@ export function buildSavePayload(input: BuildSavePayloadInput) {
|
||||
header_craft_state: headerCraftState,
|
||||
footer_craft_state: footerCraftState,
|
||||
pages_craft_state: pagesGrapesjs,
|
||||
head_code: headCode,
|
||||
design,
|
||||
};
|
||||
}
|
||||
|
||||
@@ -191,6 +200,7 @@ export function useWhpApi() {
|
||||
setPagesCraftState,
|
||||
setActivePageIdDirect,
|
||||
} = usePages();
|
||||
const { design, updateDesign } = useSiteDesign();
|
||||
|
||||
const save = useCallback(async () => {
|
||||
if (!isWHP || !whpConfig) return null;
|
||||
@@ -210,6 +220,8 @@ export function useWhpApi() {
|
||||
activePageId,
|
||||
isEditingHeader,
|
||||
isEditingFooter,
|
||||
headCode: design.headCode,
|
||||
design,
|
||||
});
|
||||
|
||||
const resp = await fetch(`${whpConfig.apiUrl}?action=save`, {
|
||||
@@ -221,7 +233,7 @@ export function useWhpApi() {
|
||||
body: JSON.stringify(payload),
|
||||
});
|
||||
return resp.json();
|
||||
}, [isWHP, whpConfig, query, pages, activePageId, headerPage, footerPage, isEditingHeader, isEditingFooter]);
|
||||
}, [isWHP, whpConfig, query, pages, activePageId, headerPage, footerPage, isEditingHeader, isEditingFooter, design]);
|
||||
|
||||
const publish = useCallback(async () => {
|
||||
if (!isWHP || !whpConfig) return null;
|
||||
@@ -255,6 +267,17 @@ export function useWhpApi() {
|
||||
if (data.success && data.project) {
|
||||
const proj = data.project;
|
||||
|
||||
// Restore site design tokens (colors/fonts/headCode) so the editor
|
||||
// reflects what was last saved. Prefer the full `design` object when
|
||||
// present; fall back to just `head_code` for older project.json files
|
||||
// saved before this field existed (backward-compatible: defaults for
|
||||
// everything else).
|
||||
if (proj.design && typeof proj.design === 'object') {
|
||||
updateDesign(proj.design);
|
||||
} else if (typeof proj.head_code === 'string') {
|
||||
updateDesign({ headCode: proj.head_code });
|
||||
}
|
||||
|
||||
// Restore header craft state
|
||||
if (proj.header_craft_state) {
|
||||
setHeaderCraftState(typeof proj.header_craft_state === 'string'
|
||||
@@ -300,7 +323,7 @@ export function useWhpApi() {
|
||||
}
|
||||
}
|
||||
return data;
|
||||
}, [isWHP, whpConfig, actions, setHeaderCraftState, setFooterCraftState, setPagesCraftState, setActivePageIdDirect, isEditingHeader, isEditingFooter]);
|
||||
}, [isWHP, whpConfig, actions, setHeaderCraftState, setFooterCraftState, setPagesCraftState, setActivePageIdDirect, isEditingHeader, isEditingFooter, updateDesign]);
|
||||
|
||||
const uploadAsset = useCallback(
|
||||
async (file: File) => {
|
||||
|
||||
@@ -16,6 +16,8 @@ interface ContextMenuProps {
|
||||
|
||||
interface MenuItem {
|
||||
label: string;
|
||||
/** Font Awesome icon suffix (e.g. 'magic' for fa-magic), rendered before the label. */
|
||||
icon?: string;
|
||||
shortcut?: string;
|
||||
action: () => void;
|
||||
danger?: boolean;
|
||||
@@ -189,7 +191,8 @@ export const ContextMenu: React.FC<ContextMenuProps> = ({
|
||||
|
||||
const items: MenuItem[] = [
|
||||
{
|
||||
label: '✨ Ask Sitesmith',
|
||||
label: 'Ask Sitesmith',
|
||||
icon: 'magic',
|
||||
action: askSitesmith,
|
||||
disabled: isRoot,
|
||||
dividerAfter: true,
|
||||
@@ -291,7 +294,10 @@ export const ContextMenu: React.FC<ContextMenuProps> = ({
|
||||
(e.target as HTMLElement).style.background = 'transparent';
|
||||
}}
|
||||
>
|
||||
<span>{item.label}</span>
|
||||
<span>
|
||||
{item.icon && <i className={`fa fa-${item.icon}`} style={{ marginRight: 6, width: 12 }} />}
|
||||
{item.label}
|
||||
</span>
|
||||
{item.shortcut && (
|
||||
<span
|
||||
style={{
|
||||
|
||||
@@ -107,23 +107,39 @@ export const AssetsPanel: React.FC = () => {
|
||||
{loading ? 'Uploading...' : 'Upload File'}
|
||||
</button>
|
||||
|
||||
{/* Drop zone */}
|
||||
{/* Drop zone -- a single element that doubles as the empty state.
|
||||
Previously this was a small always-visible dropzone PLUS a
|
||||
separate italic "No assets uploaded yet" line stacked underneath
|
||||
it when empty; merged into one tall dropzone (icon + copy,
|
||||
click-or-drag) so the empty state isn't two redundant messages.
|
||||
Once assets exist it collapses back to a slim persistent drop
|
||||
target above the grid. */}
|
||||
<div
|
||||
onDrop={handleDrop}
|
||||
onDragOver={handleDragOver}
|
||||
onDragLeave={handleDragLeave}
|
||||
{...(assets.length === 0 ? clickableProps(() => fileInputRef.current?.click()) : {})}
|
||||
style={{
|
||||
padding: 20,
|
||||
display: 'flex',
|
||||
flexDirection: 'column',
|
||||
alignItems: 'center',
|
||||
justifyContent: 'center',
|
||||
gap: 8,
|
||||
padding: assets.length === 0 ? '36px 20px' : 16,
|
||||
border: `2px dashed ${isDragOver ? 'var(--color-accent)' : 'var(--color-border)'}`,
|
||||
borderRadius: 'var(--radius-md)',
|
||||
background: isDragOver ? 'var(--color-accent-subtle)' : 'transparent',
|
||||
textAlign: 'center',
|
||||
color: isDragOver ? 'var(--color-accent)' : 'var(--color-text-dim)',
|
||||
fontSize: 11,
|
||||
cursor: assets.length === 0 ? 'pointer' : 'default',
|
||||
transition: 'all var(--transition-fast)',
|
||||
}}
|
||||
>
|
||||
Drop files here to upload
|
||||
{assets.length === 0 && (
|
||||
<i className="fa fa-cloud-upload" aria-hidden style={{ fontSize: 28, opacity: 0.5 }} />
|
||||
)}
|
||||
{assets.length === 0 ? 'Drag images here or click to upload' : 'Drop files here to upload'}
|
||||
</div>
|
||||
|
||||
{/* Error message */}
|
||||
@@ -143,20 +159,6 @@ export const AssetsPanel: React.FC = () => {
|
||||
)}
|
||||
|
||||
{/* Asset grid */}
|
||||
{assets.length === 0 && !loading && (
|
||||
<div
|
||||
style={{
|
||||
textAlign: 'center',
|
||||
padding: 20,
|
||||
color: 'var(--color-text-dim)',
|
||||
fontSize: 12,
|
||||
fontStyle: 'italic',
|
||||
}}
|
||||
>
|
||||
No assets uploaded yet
|
||||
</div>
|
||||
)}
|
||||
|
||||
<div
|
||||
style={{
|
||||
display: 'grid',
|
||||
@@ -296,7 +298,7 @@ export const AssetsPanel: React.FC = () => {
|
||||
cursor: 'pointer',
|
||||
}}
|
||||
>
|
||||
✕
|
||||
<i className="fa fa-times" aria-hidden />
|
||||
</button>
|
||||
</div>
|
||||
) : (
|
||||
@@ -328,7 +330,7 @@ export const AssetsPanel: React.FC = () => {
|
||||
onMouseEnter={(e) => { (e.target as HTMLElement).style.opacity = '1'; }}
|
||||
onMouseLeave={(e) => { (e.target as HTMLElement).style.opacity = '0.7'; }}
|
||||
>
|
||||
✕
|
||||
<i className="fa fa-times" aria-hidden />
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
|
||||
@@ -123,7 +123,7 @@ const categories: CategoryDef[] = [
|
||||
label: 'Media',
|
||||
blocks: [
|
||||
{ id: 'image', label: 'Image', icon: 'fa-image',
|
||||
component: <ImageBlock src="" alt="Image" style={{ maxWidth: '100%', height: 'auto', display: 'block', borderRadius: '8px' }} /> },
|
||||
component: <ImageBlock alt="Image" style={{ maxWidth: '100%', height: 'auto', display: 'block', borderRadius: '8px' }} /> },
|
||||
{ id: 'video', label: 'Video', icon: 'fa-play-circle',
|
||||
component: <VideoBlock videoUrl="" isBackground={false} /> },
|
||||
{ id: 'map-embed', label: 'Map', icon: 'fa-map-marker',
|
||||
|
||||
@@ -394,7 +394,7 @@ export const PagesPanel: React.FC = () => {
|
||||
cursor: 'pointer',
|
||||
}}
|
||||
>
|
||||
✕
|
||||
<i className="fa fa-trash" aria-hidden="true" />
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
|
||||
@@ -11,6 +11,7 @@ import {
|
||||
useNodeProp,
|
||||
} from './shared';
|
||||
import { AssetPicker } from '../../../ui/AssetPicker';
|
||||
import { PLACEHOLDER_SRC } from '../../../components/media/ImageBlock';
|
||||
|
||||
/* ---------- IMAGE (with upload/browse/drop) ---------- */
|
||||
export const ImageStylePanel: React.FC<StylePanelProps> = ({ selectedId, nodeProps }) => {
|
||||
@@ -33,7 +34,7 @@ export const ImageStylePanel: React.FC<StylePanelProps> = ({ selectedId, nodePro
|
||||
<SectionLabel>Image Source</SectionLabel>
|
||||
<AssetPicker
|
||||
value={nodeProps.src || ''}
|
||||
onChange={(url) => actions.setProp(selectedId, (props: any) => { props.src = url; })}
|
||||
onChange={(url) => actions.setProp(selectedId, (props: any) => { props.src = url || PLACEHOLDER_SRC; })}
|
||||
variant="full"
|
||||
/>
|
||||
</div>
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
import { describe, it, expect } from 'vitest';
|
||||
import { defaultPresetGridColumns } from './shared';
|
||||
import { RADIUS_PRESETS, SPACING_PRESETS, IMAGE_RADIUS_PRESETS, FONT_WEIGHTS, TEXT_SIZES, FONT_FAMILIES } from '../../../constants/presets';
|
||||
|
||||
/*
|
||||
* Regression: 5-item preset sets (RADIUS_PRESETS, SPACING_PRESETS,
|
||||
* IMAGE_RADIUS_PRESETS, FONT_WEIGHTS, and NavStylePanel's ad-hoc
|
||||
* GAP_PRESETS) left a lone orphan button on its own row under the old
|
||||
* fixed 4-column .preset-grid. PresetButtonGrid now derives a column
|
||||
* count from the preset length instead.
|
||||
*/
|
||||
describe('defaultPresetGridColumns', () => {
|
||||
it('gives 5-item sets their own single row (no orphan)', () => {
|
||||
expect(defaultPresetGridColumns(RADIUS_PRESETS.length)).toBe(5);
|
||||
expect(defaultPresetGridColumns(SPACING_PRESETS.length)).toBe(5);
|
||||
expect(defaultPresetGridColumns(IMAGE_RADIUS_PRESETS.length)).toBe(5);
|
||||
expect(defaultPresetGridColumns(FONT_WEIGHTS.length)).toBe(5);
|
||||
expect(defaultPresetGridColumns(5)).toBe(5); // NavStylePanel's GAP_PRESETS
|
||||
});
|
||||
|
||||
it('splits 6-item sets into two even rows of 3 (was 4+2 uneven)', () => {
|
||||
expect(defaultPresetGridColumns(TEXT_SIZES.length)).toBe(3);
|
||||
});
|
||||
|
||||
it('keeps the classic 4-column grid for sets that already divide evenly', () => {
|
||||
expect(defaultPresetGridColumns(FONT_FAMILIES.length)).toBe(4); // 8 items
|
||||
expect(defaultPresetGridColumns(4)).toBe(4);
|
||||
expect(defaultPresetGridColumns(3)).toBe(4);
|
||||
});
|
||||
|
||||
it('never leaves a single orphan on the final row for any count 1-12', () => {
|
||||
for (let n = 1; n <= 12; n++) {
|
||||
const cols = defaultPresetGridColumns(n);
|
||||
const isLoneOrphan = n > cols && n % cols === 1;
|
||||
expect(isLoneOrphan).toBe(false);
|
||||
}
|
||||
});
|
||||
});
|
||||
@@ -84,9 +84,30 @@ interface PresetButtonGridProps {
|
||||
presets: { label: string; value: string }[];
|
||||
activeValue: string | undefined;
|
||||
onSelect: (value: string) => void;
|
||||
/** Explicit column count. When omitted, a column count is derived from
|
||||
* `presets.length` (see `defaultPresetGridColumns`) so odd-sized preset
|
||||
* sets (5, 6, ...) don't leave a lone orphan button dangling on its own
|
||||
* row under the fixed 4-column grid. */
|
||||
columns?: number;
|
||||
}
|
||||
export const PresetButtonGrid: React.FC<PresetButtonGridProps> = ({ presets, activeValue, onSelect }) => (
|
||||
<div className="preset-grid">
|
||||
|
||||
/** Picks a column count that avoids a single orphan on the last row.
|
||||
* 4-or-fewer presets keep the classic single row of 4. 5 gets its own
|
||||
* row (5 cols). 6 splits into two even rows of 3. Anything else falls
|
||||
* back to a 4- or 3-column grid depending on which divides evenly. */
|
||||
export function defaultPresetGridColumns(count: number): number {
|
||||
if (count <= 4) return 4;
|
||||
if (count === 5) return 5;
|
||||
if (count === 6) return 3;
|
||||
if (count % 4 === 0) return 4;
|
||||
if (count % 3 === 0) return 3;
|
||||
return 4;
|
||||
}
|
||||
|
||||
export const PresetButtonGrid: React.FC<PresetButtonGridProps> = ({ presets, activeValue, onSelect, columns }) => {
|
||||
const cols = columns ?? defaultPresetGridColumns(presets.length);
|
||||
return (
|
||||
<div className="preset-grid" style={{ gridTemplateColumns: `repeat(${cols}, 1fr)` }}>
|
||||
{presets.map((p) => (
|
||||
<button
|
||||
key={p.value}
|
||||
@@ -98,6 +119,7 @@ export const PresetButtonGrid: React.FC<PresetButtonGridProps> = ({ presets, act
|
||||
))}
|
||||
</div>
|
||||
);
|
||||
};
|
||||
|
||||
interface GradientSwatchGridProps {
|
||||
activeValue: string | undefined;
|
||||
|
||||
@@ -21,8 +21,8 @@ export const SitesmithButton: React.FC<Props> = ({ onClick }) => {
|
||||
color: '#fff', border: 'none', padding: '6px 12px', borderRadius: 6, cursor: 'pointer', fontWeight: 500,
|
||||
}}
|
||||
>
|
||||
✨ Sitesmith
|
||||
{locked && <span aria-hidden style={{ marginLeft: 6, fontSize: 12 }}>🔒</span>}
|
||||
<i className="fa fa-magic" aria-hidden style={{ marginRight: 6 }} /> Sitesmith
|
||||
{locked && <i className="fa fa-lock" aria-hidden style={{ marginLeft: 6, fontSize: 12 }} />}
|
||||
{capped && !locked && <span aria-hidden style={{ marginLeft: 6, fontSize: 11, opacity: 0.85 }}>(cap)</span>}
|
||||
</button>
|
||||
);
|
||||
|
||||
@@ -103,7 +103,10 @@ export const SitesmithModal: React.FC<Props> = ({ onClose, target }) => {
|
||||
>
|
||||
<div style={panel}>
|
||||
<div style={header}>
|
||||
<div style={{ fontWeight: 600, color: '#fff' }}>✨ Sitesmith</div>
|
||||
<div style={{ fontWeight: 600, color: '#fff' }}>
|
||||
<i className="fa fa-magic" aria-hidden style={{ marginRight: 6 }} />
|
||||
Sitesmith
|
||||
</div>
|
||||
{summary && summary.enabled && (
|
||||
<div style={{ fontSize: 12, color: '#a1a1aa', marginLeft: 16 }}>
|
||||
{summary.monthly_used} / {summary.monthly_cap} this month
|
||||
@@ -136,7 +139,7 @@ export const SitesmithModal: React.FC<Props> = ({ onClose, target }) => {
|
||||
</button>
|
||||
)
|
||||
)}
|
||||
<button onClick={onClose} aria-label="Close" style={closeBtn}>✕</button>
|
||||
<button onClick={onClose} aria-label="Close" style={closeBtn}><i className="fa fa-times" aria-hidden /></button>
|
||||
</div>
|
||||
<div style={body}>
|
||||
<UpgradeBanner summary={summary} />
|
||||
|
||||
@@ -248,7 +248,7 @@ export const TemplateModal: React.FC<TemplateModalProps> = ({ open, onClose }) =
|
||||
</p>
|
||||
</div>
|
||||
<button onClick={onClose} style={closeButtonStyle} title="Close">
|
||||
✕
|
||||
<i className="fa fa-times" aria-hidden />
|
||||
</button>
|
||||
</div>
|
||||
|
||||
|
||||
@@ -2,7 +2,7 @@ import { describe, test, expect, vi, beforeEach, afterEach } from 'vitest';
|
||||
import React from 'react';
|
||||
import { createRoot, Root } from 'react-dom/client';
|
||||
import { act } from 'react-dom/test-utils';
|
||||
import { PageProvider, usePages, uniqueSlug } from './PageContext';
|
||||
import { PageProvider, usePages, uniqueSlug, nextPageId } from './PageContext';
|
||||
|
||||
/* PageContext only needs `useEditor` from @craftjs/core (for query.serialize /
|
||||
actions.deserialize during page switches) — mock just that so PageProvider
|
||||
@@ -15,11 +15,10 @@ vi.mock('@craftjs/core', () => ({
|
||||
}),
|
||||
}));
|
||||
|
||||
/* addPage mints ids from `Date.now()`. Two adds inside the same test can land
|
||||
in the same millisecond and collide on id, which is an existing, unrelated
|
||||
bug (id collision, not slug collision) — out of scope here but it makes
|
||||
these tests flaky since a colliding id defeats the "other pages" slug
|
||||
lookup. Force distinct ids so the slug-dedupe assertions below are stable. */
|
||||
/* addPage mints ids via nextPageId() (timestamp + monotonic counter, M-3),
|
||||
so same-millisecond calls no longer collide on id. Date.now() is still
|
||||
pinned/advanced here for determinism across the slug-dedupe assertions
|
||||
below, independent of wall-clock timing. */
|
||||
let dateNowSpy: ReturnType<typeof vi.spyOn>;
|
||||
beforeEach(() => {
|
||||
let counter = 1_700_000_000_000;
|
||||
@@ -48,6 +47,23 @@ function unmount() {
|
||||
container.remove();
|
||||
}
|
||||
|
||||
describe('nextPageId (M-3: no same-millisecond id collision)', () => {
|
||||
test('two calls yield distinct ids even when Date.now() is pinned to a constant', () => {
|
||||
const spy = vi.spyOn(Date, 'now').mockReturnValue(1_700_000_000_000);
|
||||
try {
|
||||
const id1 = nextPageId();
|
||||
const id2 = nextPageId();
|
||||
expect(id1).not.toBe(id2);
|
||||
} finally {
|
||||
spy.mockRestore();
|
||||
}
|
||||
});
|
||||
|
||||
test('ids are prefixed with "page_"', () => {
|
||||
expect(nextPageId()).toMatch(/^page_/);
|
||||
});
|
||||
});
|
||||
|
||||
describe('uniqueSlug', () => {
|
||||
test('returns base unchanged when no collision', () => {
|
||||
expect(uniqueSlug('about', ['index', 'contact'])).toBe('about');
|
||||
|
||||
@@ -43,6 +43,20 @@ interface PageContextValue {
|
||||
const HEADER_ID = '__header__';
|
||||
const FOOTER_ID = '__footer__';
|
||||
|
||||
// M-3: `page_${Date.now()}` alone collides when two pages are minted inside
|
||||
// the same millisecond (addPage called twice in quick succession, or two AI
|
||||
// replaceAllPages entries) -- then rename/delete/save operate on both pages
|
||||
// at once since they share an id. A module-scoped monotonic counter,
|
||||
// combined with the timestamp, guarantees uniqueness regardless of how many
|
||||
// ids are minted within the same millisecond. This is state/id-minting code
|
||||
// (not toHtml/export), so Date.now() here is fine -- see task-minors-brief.md.
|
||||
let pageIdCounter = 0;
|
||||
|
||||
/** Mints a unique page id: timestamp (base36) + a monotonic per-process counter (base36). */
|
||||
export function nextPageId(): string {
|
||||
return 'page_' + Date.now().toString(36) + '_' + (++pageIdCounter).toString(36);
|
||||
}
|
||||
|
||||
const EMPTY_CANVAS =
|
||||
'{"ROOT":{"type":{"resolvedName":"Container"},"isCanvas":true,"props":{"style":{"minHeight":"100vh","backgroundColor":"#ffffff"},"tag":"div"},"displayName":"Container","custom":{},"hidden":false,"nodes":[],"linkedNodes":{}}}';
|
||||
|
||||
@@ -338,7 +352,7 @@ export const PageProvider: React.FC<{ children: ReactNode }> = ({ children }) =>
|
||||
const addPage = useCallback(
|
||||
(name: string, slug: string) => {
|
||||
const requestedSlug = slug || slugify(name);
|
||||
const id = `page_${Date.now()}`;
|
||||
const id = nextPageId();
|
||||
|
||||
// Save current page first
|
||||
saveCurrentState();
|
||||
@@ -452,7 +466,7 @@ export const PageProvider: React.FC<{ children: ReactNode }> = ({ children }) =>
|
||||
const slug = i === 0 ? 'index' : uniqueSlug(slugify(p.name), seenSlugs);
|
||||
seenSlugs.push(slug);
|
||||
return {
|
||||
id: i === 0 ? 'home' : `page_${Date.now()}_${i}`,
|
||||
id: i === 0 ? 'home' : nextPageId(),
|
||||
name: p.name,
|
||||
slug,
|
||||
craftState: treeToCraftState(p.tree),
|
||||
|
||||
@@ -16,8 +16,8 @@
|
||||
--color-border: #2d2d3a;
|
||||
--color-border-light: #3f3f46;
|
||||
--color-text: #e4e4e7;
|
||||
--color-text-muted: #71717a;
|
||||
--color-text-dim: #52525b;
|
||||
--color-text-muted: #8b8b96;
|
||||
--color-text-dim: #6e6e78;
|
||||
--color-accent: #3b82f6;
|
||||
--color-accent-hover: #2563eb;
|
||||
--color-accent-subtle: rgba(59, 130, 246, 0.12);
|
||||
@@ -704,7 +704,7 @@ body {
|
||||
}
|
||||
|
||||
.block-item-icon {
|
||||
font-size: 18px;
|
||||
font-size: 20px;
|
||||
color: var(--color-text-muted);
|
||||
transition: color var(--transition-fast);
|
||||
}
|
||||
@@ -714,7 +714,7 @@ body {
|
||||
}
|
||||
|
||||
.block-item-label {
|
||||
font-size: 10px;
|
||||
font-size: 11px;
|
||||
font-weight: 500;
|
||||
color: var(--color-text-muted);
|
||||
text-align: center;
|
||||
@@ -1074,12 +1074,16 @@ body {
|
||||
outline-offset: -1px;
|
||||
}
|
||||
|
||||
/* Component indicator badge */
|
||||
/* Component indicator badge (floats over the selected node via a portal --
|
||||
position/top/left are set inline per-node, see RenderNode.tsx) */
|
||||
.component-indicator {
|
||||
position: absolute;
|
||||
top: -22px;
|
||||
left: 0;
|
||||
padding: 2px 8px;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 6px;
|
||||
padding: 2px 6px 2px 8px;
|
||||
font-size: 10px;
|
||||
font-weight: 600;
|
||||
color: #ffffff;
|
||||
@@ -1090,6 +1094,28 @@ body {
|
||||
z-index: 10;
|
||||
}
|
||||
|
||||
.component-indicator-parent-btn {
|
||||
display: inline-flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
width: 14px;
|
||||
height: 14px;
|
||||
padding: 0;
|
||||
border: none;
|
||||
border-radius: 2px;
|
||||
background: rgba(255, 255, 255, 0.2);
|
||||
color: #ffffff;
|
||||
font-size: 8px;
|
||||
line-height: 1;
|
||||
cursor: pointer;
|
||||
pointer-events: auto;
|
||||
transition: background var(--transition-fast);
|
||||
}
|
||||
|
||||
.component-indicator-parent-btn:hover {
|
||||
background: rgba(255, 255, 255, 0.4);
|
||||
}
|
||||
|
||||
/* --------------------------------------------------------------------------
|
||||
Scrollbar Styling
|
||||
-------------------------------------------------------------------------- */
|
||||
@@ -1225,6 +1251,8 @@ body {
|
||||
Empty Canvas State
|
||||
-------------------------------------------------------------------------- */
|
||||
.empty-canvas-hint {
|
||||
position: absolute;
|
||||
inset: 0;
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
align-items: center;
|
||||
@@ -1234,6 +1262,9 @@ body {
|
||||
font-size: 13px;
|
||||
text-align: center;
|
||||
gap: 12px;
|
||||
/* Overlays the drop area without intercepting drags/clicks meant for the
|
||||
underlying (empty) canvas root -- see Canvas.tsx. */
|
||||
pointer-events: none;
|
||||
}
|
||||
|
||||
.empty-canvas-hint i {
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
import { describe, test, expect } from 'vitest';
|
||||
import { escapeHtml, escapeAttr, safeUrl, stableHash, scopeId, sanitizeFormMethod, sanitizeInputType } from './escape';
|
||||
import { escapeHtml, escapeAttr, safeUrl, safeImageUrl, stableHash, scopeId, sanitizeFormMethod, sanitizeInputType } from './escape';
|
||||
|
||||
describe('escapeHtml', () => {
|
||||
test('escapes &, <, >, "', () => {
|
||||
@@ -71,6 +71,24 @@ describe('safeUrl', () => {
|
||||
expect(safeUrl(s)).toBe(s);
|
||||
});
|
||||
|
||||
test('M-5: blocks data:image/svg+xml (can execute script when navigated to directly)', () => {
|
||||
expect(safeUrl('data:image/svg+xml,<svg onload=alert(1)>')).toBe('');
|
||||
});
|
||||
|
||||
test('M-5: blocks data:image/svg+xml;base64 variant', () => {
|
||||
expect(safeUrl('data:image/svg+xml;base64,PHN2ZyBvbmxvYWQ9YWxlcnQoMSk+')).toBe('');
|
||||
});
|
||||
|
||||
test('M-5: blocks obfuscated (whitespace/case) data:image/svg+xml', () => {
|
||||
expect(safeUrl(' DATA:IMAGE/SVG+XML,<svg onload=alert(1)>')).toBe('');
|
||||
});
|
||||
|
||||
test('M-5: still allows other data:image/* types unchanged', () => {
|
||||
expect(safeUrl('data:image/jpeg;base64,/9j/4AAQ')).toBe('data:image/jpeg;base64,/9j/4AAQ');
|
||||
expect(safeUrl('data:image/gif;base64,R0lGOD')).toBe('data:image/gif;base64,R0lGOD');
|
||||
expect(safeUrl('data:image/webp;base64,UklGR')).toBe('data:image/webp;base64,UklGR');
|
||||
});
|
||||
|
||||
test.each([
|
||||
'https://x.com/a?b=1&c=2',
|
||||
'http://x',
|
||||
@@ -94,6 +112,73 @@ describe('safeUrl', () => {
|
||||
});
|
||||
});
|
||||
|
||||
describe('safeImageUrl (Bug 2: image-context sink -- data:image/svg+xml is safe as an <img>/CSS url() target)', () => {
|
||||
test('allows data:image/svg+xml (a raw, non-base64 SVG data URI, as Gallery/ImageBlock placeholders use)', () => {
|
||||
const s = 'data:image/svg+xml,<svg/>';
|
||||
expect(safeImageUrl(s)).toBe(s);
|
||||
});
|
||||
|
||||
test('allows data:image/svg+xml;base64 variant', () => {
|
||||
const s = 'data:image/svg+xml;base64,PHN2Zy8+';
|
||||
expect(safeImageUrl(s)).toBe(s);
|
||||
});
|
||||
|
||||
test('allows other data:image/* types unchanged', () => {
|
||||
expect(safeImageUrl('data:image/png;base64,x')).toBe('data:image/png;base64,x');
|
||||
expect(safeImageUrl('data:image/jpeg;base64,x')).toBe('data:image/jpeg;base64,x');
|
||||
expect(safeImageUrl('data:image/webp;base64,x')).toBe('data:image/webp;base64,x');
|
||||
expect(safeImageUrl('data:image/gif;base64,x')).toBe('data:image/gif;base64,x');
|
||||
});
|
||||
|
||||
test('still blocks javascript: scheme', () => {
|
||||
expect(safeImageUrl('javascript:alert(1)')).toBe('');
|
||||
});
|
||||
|
||||
test('still blocks vbscript: scheme', () => {
|
||||
expect(safeImageUrl('vbscript:msgbox(1)')).toBe('');
|
||||
});
|
||||
|
||||
test('still blocks data:text/html', () => {
|
||||
expect(safeImageUrl('data:text/html,x')).toBe('');
|
||||
});
|
||||
|
||||
test('still blocks non-image data: types generally (e.g. data:application/...)', () => {
|
||||
expect(safeImageUrl('data:application/javascript,alert(1)')).toBe('');
|
||||
});
|
||||
|
||||
test('blocks obfuscated (whitespace/case) javascript: scheme, same as safeUrl', () => {
|
||||
expect(safeImageUrl(' JavaScript:alert(1)')).toBe('');
|
||||
expect(safeImageUrl('java\tscript:alert(1)')).toBe('');
|
||||
expect(safeImageUrl('javascript:alert(1)')).toBe('');
|
||||
});
|
||||
|
||||
test('allows ordinary http(s)/relative urls unchanged, same as safeUrl', () => {
|
||||
expect(safeImageUrl('https://example.com/photo.jpg')).toBe('https://example.com/photo.jpg');
|
||||
expect(safeImageUrl('/assets/photo.jpg')).toBe('/assets/photo.jpg');
|
||||
expect(safeImageUrl('')).toBe('');
|
||||
});
|
||||
|
||||
test('coerces non-string to empty string', () => {
|
||||
expect(safeImageUrl(null as any)).toBe('');
|
||||
expect(safeImageUrl(undefined as any)).toBe('');
|
||||
});
|
||||
|
||||
test('tightened allowlist: blocks a bogus MIME that merely starts with "image" but has no slash (e.g. data:imagehtml/...)', () => {
|
||||
expect(safeImageUrl('data:imagehtml/svg+xml,x')).toBe('');
|
||||
});
|
||||
|
||||
test('tightened allowlist: still allows legit data:image/* subtypes', () => {
|
||||
expect(safeImageUrl('data:image/png;base64,x')).toBe('data:image/png;base64,x');
|
||||
expect(safeImageUrl('data:image/svg+xml,<svg/>')).toBe('data:image/svg+xml,<svg/>');
|
||||
});
|
||||
});
|
||||
|
||||
describe('safeUrl still blocks data:image/svg+xml (href/iframe/navigation context unchanged by safeImageUrl addition)', () => {
|
||||
test('safeUrl(data:image/svg+xml,...) is still blocked', () => {
|
||||
expect(safeUrl('data:image/svg+xml,<svg onload=alert(1)>')).toBe('');
|
||||
});
|
||||
});
|
||||
|
||||
describe('stableHash', () => {
|
||||
test('same input always produces the same output', () => {
|
||||
expect(stableHash('hello')).toBe(stableHash('hello'));
|
||||
@@ -120,8 +205,24 @@ describe('scopeId', () => {
|
||||
expect(id1).not.toBe(id2);
|
||||
});
|
||||
|
||||
test('node id is slugified (non-alphanumeric characters stripped, lowercased)', () => {
|
||||
expect(scopeId('Node ID! 123', 'seed', 'sb')).toBe('sb_nodeid123');
|
||||
test('output is a valid CSS ident: prefix_hash', () => {
|
||||
expect(scopeId('Node ID! 123', 'seed', 'sb')).toMatch(/^sb_[a-z0-9]+$/);
|
||||
});
|
||||
|
||||
test('M-4: case-differing node ids do not collapse to the same scope (no case-fold collision)', () => {
|
||||
expect(scopeId('AbC', 'seed', 'sb')).not.toBe(scopeId('abc', 'seed', 'sb'));
|
||||
});
|
||||
|
||||
test('M-4: punctuation-differing node ids do not collapse to the same scope', () => {
|
||||
expect(scopeId('a-b', 'seed', 'sb')).not.toBe(scopeId('ab', 'seed', 'sb'));
|
||||
});
|
||||
|
||||
test('M-4: same input always yields the identical scope id', () => {
|
||||
expect(scopeId('some-node-id', 'seed', 'sb')).toBe(scopeId('some-node-id', 'seed', 'sb'));
|
||||
});
|
||||
|
||||
test('M-4: output always matches a valid CSS ident pattern', () => {
|
||||
expect(scopeId('Weird!! Node--ID__123', 'seed', 'sb')).toMatch(/^[a-z]+_[a-z0-9]+$/i);
|
||||
});
|
||||
|
||||
test('no nodeId (legacy 2-arg call sites) falls back to a deterministic hash of the seed, not Math.random', () => {
|
||||
|
||||
+72
-17
@@ -36,7 +36,14 @@ export function escapeAttr(s: string): string {
|
||||
// Dangerous scheme prefixes, checked against a normalized copy with all
|
||||
// colons removed (see safeUrl) so that colon-splicing obfuscation like
|
||||
// "java:script:alert(1)" can't slip past a literal "javascript:" check.
|
||||
const DANGEROUS_SCHEME_PREFIXES = ['javascript', 'vbscript', 'datatext/html'];
|
||||
// M-5: `data:image/svg+xml` is blocked alongside `data:text/html` -- an SVG
|
||||
// document can carry an inline <script>/onload= just like an HTML document,
|
||||
// so it executes script when loaded as a document/navigation target (e.g. an
|
||||
// <a href> or window.open), even though it's nominally an "image" MIME type.
|
||||
// Other `data:image/*` types (png/jpeg/gif/webp, ...) stay allowed below --
|
||||
// only this specific scriptable subtype is blocked, regardless of a
|
||||
// trailing `;base64` or other parameters.
|
||||
const DANGEROUS_SCHEME_PREFIXES = ['javascript', 'vbscript', 'datatext/html', 'dataimage/svg+xml'];
|
||||
|
||||
/** Decodes &#NN; and &#xNN; numeric HTML entities (used to obfuscate scheme names). */
|
||||
function decodeNumericEntities(s: string): string {
|
||||
@@ -57,20 +64,7 @@ export function safeUrl(s: string): string {
|
||||
const trimmed = s.trim();
|
||||
if (trimmed === '') return '';
|
||||
|
||||
// Build a normalized copy for scheme detection only: decode numeric HTML
|
||||
// entities (catches e.g. j -> 'j'), strip whitespace/control chars,
|
||||
// and lowercase.
|
||||
const normalized = decodeNumericEntities(trimmed)
|
||||
.replace(/[\x00-\x20]+/g, '')
|
||||
.toLowerCase();
|
||||
|
||||
// Strip any colons before matching the scheme prefix. This defeats
|
||||
// obfuscation that splices extra colons into the scheme name itself
|
||||
// (e.g. decoding : mid-word produces "java:script:alert(1)", which
|
||||
// would otherwise dodge a literal "^javascript:" check) while still
|
||||
// reliably catching the real "javascript:"/"vbscript:"/"data:text/html"
|
||||
// prefixes once their own colon is removed.
|
||||
const collapsed = normalized.replace(/:/g, '');
|
||||
const collapsed = normalizeForSchemeCheck(trimmed);
|
||||
|
||||
if (DANGEROUS_SCHEME_PREFIXES.some((prefix) => collapsed.startsWith(prefix))) {
|
||||
return '';
|
||||
@@ -79,6 +73,61 @@ export function safeUrl(s: string): string {
|
||||
return trimmed;
|
||||
}
|
||||
|
||||
/**
|
||||
* Image-context variant of `safeUrl` for IMAGE sinks only (`<img src>`, CSS
|
||||
* `url(...)` backgrounds). `data:image/svg+xml` is safe here -- loaded as an
|
||||
* image, an SVG is rasterized and never executes an inline <script>/onload=
|
||||
* the way it would as a navigation/iframe document -- so, unlike `safeUrl`,
|
||||
* this ALLOWS every `data:image/*` subtype (svg+xml, png, jpeg, gif, webp,
|
||||
* ..., with or without `;base64`).
|
||||
*
|
||||
* Still blocks `javascript:` / `vbscript:` (same obfuscation-resistant
|
||||
* normalization as `safeUrl`), and -- because this is an image sink, not a
|
||||
* general-purpose URL sink -- treats `data:` as an ALLOWLIST rather than a
|
||||
* blocklist: any `data:` URI whose type is NOT `image/*` (`data:text/html`,
|
||||
* `data:application/javascript`, `data:text/javascript`, etc.) is blocked
|
||||
* too, since none of those are legitimate image sources.
|
||||
*
|
||||
* Do NOT use this for href/iframe/form-action/navigation sinks -- keep
|
||||
* those on `safeUrl`, which still blocks `data:image/svg+xml`.
|
||||
*/
|
||||
export function safeImageUrl(s: unknown): string {
|
||||
if (typeof s !== 'string') return '';
|
||||
|
||||
const trimmed = s.trim();
|
||||
if (trimmed === '') return '';
|
||||
|
||||
const collapsed = normalizeForSchemeCheck(trimmed);
|
||||
|
||||
if (collapsed.startsWith('javascript') || collapsed.startsWith('vbscript')) {
|
||||
return '';
|
||||
}
|
||||
if (collapsed.startsWith('data') && !collapsed.startsWith('dataimage/')) {
|
||||
// A data: URI whose MIME type isn't image/* -- e.g. data:text/html,
|
||||
// data:application/javascript, data:text/javascript. No legitimate
|
||||
// image source needs these; block unconditionally.
|
||||
return '';
|
||||
}
|
||||
|
||||
return trimmed;
|
||||
}
|
||||
|
||||
// Normalizes a trimmed URL string for scheme-prefix matching only: decodes
|
||||
// numeric HTML entities (catches e.g. j -> 'j'), strips whitespace /
|
||||
// control chars, lowercases, then strips every colon. Stripping colons
|
||||
// defeats obfuscation that splices extra colons into the scheme name itself
|
||||
// (e.g. decoding : mid-word produces "java:script:alert(1)", which would
|
||||
// otherwise dodge a literal "^javascript:" check) while still reliably
|
||||
// catching the real "javascript:"/"vbscript:"/"data:..." prefixes once their
|
||||
// own colon is removed. Used for prefix `.startsWith()` checks only -- the
|
||||
// original (non-collapsed) string is always what gets returned/emitted.
|
||||
function normalizeForSchemeCheck(trimmed: string): string {
|
||||
return decodeNumericEntities(trimmed)
|
||||
.replace(/[\x00-\x20]+/g, '')
|
||||
.toLowerCase()
|
||||
.replace(/:/g, '');
|
||||
}
|
||||
|
||||
/**
|
||||
* Neutralizes CSS-context breakout for a single design-token value (color,
|
||||
* length, gradient, etc.) so it is safe to interpolate RAW into either CSS
|
||||
@@ -151,8 +200,14 @@ export function stableHash(seed: string): string {
|
||||
* available.
|
||||
*/
|
||||
export function scopeId(nodeId: string | undefined, fallbackSeed: string, prefix: string): string {
|
||||
const slug = (nodeId || '').toString().toLowerCase().replace(/[^a-z0-9]+/g, '');
|
||||
return `${prefix}_${slug || stableHash(fallbackSeed)}`;
|
||||
// M-4: hash the raw node id (via the same djb2 `stableHash` used for the
|
||||
// fallback path below) rather than lowercasing + stripping punctuation
|
||||
// into a slug. A slug collapses distinct ids that differ only by
|
||||
// case/punctuation (e.g. "AbC" and "abc", or "a-b" and "ab") onto the same
|
||||
// scope; hashing the untouched string keeps them distinct while staying
|
||||
// deterministic and producing a valid CSS ident (prefix + '_' + [a-z0-9]+).
|
||||
const seed = (nodeId || '').toString();
|
||||
return `${prefix}_${stableHash(seed || fallbackSeed)}`;
|
||||
}
|
||||
|
||||
// Shared enum allowlists for `toHtml` attribute sinks fed by props that are
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
import { CSSProperties } from 'react';
|
||||
import { escapeAttr, safeUrl } from './escape';
|
||||
import { escapeAttr, safeImageUrl } from './escape';
|
||||
|
||||
const camelToKebab = (str: string): string =>
|
||||
str.replace(/[A-Z]/g, (m) => '-' + m.toLowerCase());
|
||||
@@ -41,8 +41,12 @@ function sanitizeCssValue(raw: string): string {
|
||||
// Neutralize the url(...) reference: validate/strip the scheme and
|
||||
// re-wrap in single quotes with the contents escaped for attribute
|
||||
// safety. This is already fully safe, `;` and all.
|
||||
// Image-context sink (background/mask/border-image url()): use
|
||||
// safeImageUrl, not safeUrl -- a data:image/svg+xml background is safe
|
||||
// (rasterized, never executed as a document) and must survive here, the
|
||||
// same way it must survive on an <img src>.
|
||||
const inner = m[2];
|
||||
out += `url('${escapeAttr(safeUrl(inner.trim()))}')`;
|
||||
out += `url('${escapeAttr(safeImageUrl(inner.trim()))}')`;
|
||||
lastIndex = URL_RE.lastIndex;
|
||||
}
|
||||
out += sanitizeBreakoutChars(raw.slice(lastIndex));
|
||||
|
||||
Reference in New Issue
Block a user