import { describe, test, expect } from 'vitest'; import { Testimonials } from './Testimonials'; const toHtml = (Testimonials as any).toHtml; const testimonials = [ { quote: 'Quote one', name: 'Name One', title: 'Title One', rating: 5 }, { quote: 'Quote two', name: 'Name Two', title: 'Title Two', rating: 4 }, { quote: 'Quote three', name: 'Name Three', title: 'Title Three', rating: 3 }, ]; describe('Testimonials.toHtml single-layout export parity', () => { // The editor's "single" layout shows exactly one testimonial (a single // card, no stacked list). Static-parity fix: toHtml exports exactly one // card too (the first testimonial), matching what the editor displays by // default -- not a stacked list of all testimonials, and not a JS carousel // (this codebase's static export has no published-JS interactivity for // this component). test('single layout: exports exactly one testimonial card, not all of them', () => { const { html } = toHtml({ testimonials, layout: 'single' }, ''); expect(html).toContain('Name One'); expect(html).not.toContain('Name Two'); expect(html).not.toContain('Name Three'); expect(html).toContain('Quote one'); }); test('single layout: no carousel controls (prev/next/dots) in static export', () => { const { html } = toHtml({ testimonials, layout: 'single' }, ''); expect(html).not.toContain('fa-chevron-left'); expect(html).not.toContain('fa-chevron-right'); }); test('grid layout: still exports all testimonials (unchanged behavior)', () => { const { html } = toHtml({ testimonials, layout: 'grid' }, ''); expect(html).toContain('Name One'); expect(html).toContain('Name Two'); expect(html).toContain('Name Three'); }); }); describe('Testimonials.toHtml decorative star icons (F2.5)', () => { test('star glyphs are aria-hidden', () => { const { html } = toHtml({ testimonials, layout: 'grid' }, ''); const stars = html.match(/]*>/g) || []; expect(stars.length).toBeGreaterThan(0); stars.forEach((tag: string) => expect(tag).toContain('aria-hidden="true"')); }); }); describe('Testimonials.toHtml rating aria-label sink (attacker-controlled `rating`, typed number but unchecked)', () => { test('malicious rating value cannot break out of the star row aria-label attribute', () => { const malicious = [ { quote: 'Q', name: 'N', title: 'T', rating: '5">' as any }, ]; const { html } = toHtml({ testimonials: malicious, layout: 'grid' }, ''); expect(html).not.toContain(''); expect(html).not.toContain('5">