An adversarial pass found 5 Critical XSS sinks where props declared number/enum in TypeScript were interpolated raw into exported HTML attribute values, trusting the type — but nothing enforces it at runtime (AI update_props only validates node_id; deserialized saved state is untyped JSON). Fixed all 5 (NumberCounter data-target, StarRating aria-label, FormContainer method, ContactForm/InputField input type) plus 6 sibling sinks found by an exhaustive audit of every attribute-value interpolation across src/components: a JS-source injection into ContentSlider's inline setInterval script, a prototype-pollution-adjacent allowlist gap in Section's divider-shape lookup, TextareaField rows, Testimonials rating aria-label, HeroSimple textAlign, and MapEmbed zoom. Adds shared sanitizeFormMethod/sanitizeInputType allowlist helpers to utils/escape.ts alongside the existing escapeAttr/safeUrl/cssValue primitives. Every fix is TDD'd: a malicious-value test reproduces the raw injection against the pre-fix code, then passes after the fix. 502 tests green (npx vitest run), tsc + vite build green (npm run build). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
74 lines
3.2 KiB
TypeScript
74 lines
3.2 KiB
TypeScript
import { describe, test, expect } from 'vitest';
|
|
import { Testimonials } from './Testimonials';
|
|
|
|
const toHtml = (Testimonials as any).toHtml;
|
|
|
|
const testimonials = [
|
|
{ quote: 'Quote one', name: 'Name One', title: 'Title One', rating: 5 },
|
|
{ quote: 'Quote two', name: 'Name Two', title: 'Title Two', rating: 4 },
|
|
{ quote: 'Quote three', name: 'Name Three', title: 'Title Three', rating: 3 },
|
|
];
|
|
|
|
describe('Testimonials.toHtml single-layout export parity', () => {
|
|
// The editor's "single" layout shows exactly one testimonial (a single
|
|
// card, no stacked list). Static-parity fix: toHtml exports exactly one
|
|
// card too (the first testimonial), matching what the editor displays by
|
|
// default -- not a stacked list of all testimonials, and not a JS carousel
|
|
// (this codebase's static export has no published-JS interactivity for
|
|
// this component).
|
|
test('single layout: exports exactly one testimonial card, not all of them', () => {
|
|
const { html } = toHtml({ testimonials, layout: 'single' }, '');
|
|
expect(html).toContain('Name One');
|
|
expect(html).not.toContain('Name Two');
|
|
expect(html).not.toContain('Name Three');
|
|
expect(html).toContain('Quote one');
|
|
});
|
|
|
|
test('single layout: no carousel controls (prev/next/dots) in static export', () => {
|
|
const { html } = toHtml({ testimonials, layout: 'single' }, '');
|
|
expect(html).not.toContain('fa-chevron-left');
|
|
expect(html).not.toContain('fa-chevron-right');
|
|
});
|
|
|
|
test('grid layout: still exports all testimonials (unchanged behavior)', () => {
|
|
const { html } = toHtml({ testimonials, layout: 'grid' }, '');
|
|
expect(html).toContain('Name One');
|
|
expect(html).toContain('Name Two');
|
|
expect(html).toContain('Name Three');
|
|
});
|
|
});
|
|
|
|
describe('Testimonials.toHtml decorative star icons (F2.5)', () => {
|
|
test('star glyphs are aria-hidden', () => {
|
|
const { html } = toHtml({ testimonials, layout: 'grid' }, '');
|
|
const stars = html.match(/<i class="fa fa-star[^"]*"[^>]*>/g) || [];
|
|
expect(stars.length).toBeGreaterThan(0);
|
|
stars.forEach((tag: string) => expect(tag).toContain('aria-hidden="true"'));
|
|
});
|
|
});
|
|
|
|
describe('Testimonials.toHtml rating aria-label sink (attacker-controlled `rating`, typed number but unchecked)', () => {
|
|
test('malicious rating value cannot break out of the star row aria-label attribute', () => {
|
|
const malicious = [
|
|
{ quote: 'Q', name: 'N', title: 'T', rating: '5"><script>alert(1)</script>' as any },
|
|
];
|
|
const { html } = toHtml({ testimonials: malicious, layout: 'grid' }, '');
|
|
expect(html).not.toContain('<script>alert(1)</script>');
|
|
expect(html).not.toContain('5"><script>');
|
|
});
|
|
|
|
test('non-numeric rating falls back to a safe numeric value', () => {
|
|
const malicious = [
|
|
{ quote: 'Q', name: 'N', title: 'T', rating: 'not-a-number' as any },
|
|
];
|
|
const { html } = toHtml({ testimonials: malicious, layout: 'grid' }, '');
|
|
expect(html).toMatch(/aria-label="Rating: 0 out of 5"/);
|
|
});
|
|
|
|
test('normal numeric rating still renders correctly', () => {
|
|
const { html } = toHtml({ testimonials, layout: 'grid' }, '');
|
|
expect(html).toContain('aria-label="Rating: 5 out of 5"');
|
|
expect(html).toContain('aria-label="Rating: 4 out of 5"');
|
|
});
|
|
});
|