import { describe, test, expect } from 'vitest'; import { Footer } from './Footer'; const toHtml = (Footer as any).toHtml; describe('Footer.toHtml text escaping (attacker-controlled `text` prop)', () => { test('a tag-breakout attempt in text is neutralized (no injected element)', () => { const { html } = toHtml({ text: '' }, ''); expect(html).not.toContain(' { const { html } = toHtml({ text: 'Terms & Conditions' }, ''); expect(html).toContain('Terms & Conditions'); }); test('a normal copyright text value still renders unchanged', () => { const { html } = toHtml({ text: '© 2026 MySite. All rights reserved.' }, ''); expect(html).toContain('© 2026 MySite. All rights reserved.'); }); });