import { describe, test, expect } from 'vitest'; import { SubscribeForm } from './SubscribeForm'; const toHtml = (SubscribeForm as any).toHtml; describe('SubscribeForm.toHtml hardcoded attributes stay hardcoded (no raw prop breakout)', () => { test('form method is always POST regardless of any injected props', () => { const { html } = toHtml({ heading: 'Join us', method: 'GET">' } as any, ''); expect(html).toContain('
{ const { html } = toHtml({ type: 'text">' } as any, ''); expect(html).toContain(' { const { html: inlineHtml } = toHtml({ layout: 'inline' }, ''); const { html: stackedHtml } = toHtml({ layout: 'stacked' }, ''); expect(inlineHtml).toContain('flex-direction:row'); expect(stackedHtml).toContain('flex-direction:column'); }); test('malicious layout value cannot inject raw CSS/attribute breakout (falls through the isInline boolean check to the stacked literal)', () => { const { html } = toHtml({ layout: '">' as any }, ''); expect(html).not.toContain(' { const { html } = toHtml({ heading: 'Subscribe', placeholder: 'you@example.com', buttonText: 'Go' }, ''); expect(html).toContain('Subscribe'); expect(html).toContain('placeholder="you@example.com"'); expect(html).toContain('>Go<'); }); });