release: WRNexusJS 0.8.0
This commit is contained in:
@@ -0,0 +1,12 @@
|
||||
import { expect, test } from "bun:test";
|
||||
import { partialPrerender, streamPartialDocument } from "../src/index.ts";
|
||||
|
||||
test("partial prerender extracts and streams dynamic regions after the shell", async () => {
|
||||
const result = partialPrerender(
|
||||
'<header>Static</header><wrn-dynamic-region data-wrn-dynamic="true"><b>User</b></wrn-dynamic-region><footer>Static</footer>',
|
||||
);
|
||||
expect(result.shell).toContain("data-wrn-dynamic-placeholder");
|
||||
expect(result.regions).toEqual([{ id: "wrn-region-0", html: "<b>User</b>" }]);
|
||||
const output = await new Response(streamPartialDocument(result)).text();
|
||||
expect(output.indexOf("<header>Static</header>")).toBeLessThan(output.indexOf("<b>User</b>"));
|
||||
});
|
||||
@@ -1,5 +1,30 @@
|
||||
import { expect, test } from "bun:test";
|
||||
import { renderDocument, renderDocumentStream } from "../src/index.ts";
|
||||
import { renderDocument, renderDocumentStream, renderStoreHydration } from "../src/index.ts";
|
||||
import type { StoreContainer } from "@wrnexus/store";
|
||||
|
||||
test("store hydration is HTML-safe, bounded, redacted, and JSON-compatible", () => {
|
||||
const container = {
|
||||
serialize: () => ({
|
||||
ProfileStore: {
|
||||
display: "</script><script>alert(1)</script>",
|
||||
accessToken: "never-render-this",
|
||||
},
|
||||
}),
|
||||
} as unknown as StoreContainer;
|
||||
const html = renderStoreHydration(container, 'safe" onload="bad');
|
||||
expect(html).not.toContain("</script><script>");
|
||||
expect(html).not.toContain("never-render-this");
|
||||
expect(html).toContain('nonce="safe" onload="bad"');
|
||||
const payload = html.match(/>(.*)<\/script>$/)?.[1];
|
||||
expect(JSON.parse(payload!)).toEqual({
|
||||
ProfileStore: { display: "</script><script>alert(1)</script>", accessToken: "[REDACTED]" },
|
||||
});
|
||||
|
||||
const oversized = {
|
||||
serialize: () => ({ value: "x".repeat(300_000) }),
|
||||
} as unknown as StoreContainer;
|
||||
expect(() => renderStoreHydration(oversized)).toThrow("exceeds 262144 bytes");
|
||||
});
|
||||
|
||||
test("escapes metadata and script URLs while preserving trusted rendered body", () => {
|
||||
const html = renderDocument({
|
||||
|
||||
Reference in New Issue
Block a user