first commit
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
import { expect, test } from "bun:test";
|
||||
import { renderDocument } from "../src/index.ts";
|
||||
|
||||
test("escapes metadata and script URLs while preserving trusted rendered body", () => {
|
||||
const html = renderDocument({
|
||||
meta: { title: '</title><script>alert("x")</script>', description: '" onload="x' },
|
||||
body: "<main>trusted</main>",
|
||||
scripts: ['"><script>alert(1)</script>'],
|
||||
});
|
||||
expect(html).not.toContain('</title><script>alert("x")</script>');
|
||||
expect(html).toContain("</title>");
|
||||
expect(html).toContain("<main>trusted</main>");
|
||||
expect(html).not.toContain("<script>alert(1)</script>");
|
||||
});
|
||||
|
||||
test("deduplicates runtime scripts and module preloads", () => {
|
||||
const html = renderDocument({
|
||||
meta: { title: "Page" },
|
||||
body: "",
|
||||
scripts: ["/app.js", "/app.js"],
|
||||
});
|
||||
expect(html.match(/rel="modulepreload"/g)).toHaveLength(1);
|
||||
expect(html.match(/src="\/app\.js"/g)).toHaveLength(1);
|
||||
});
|
||||
Reference in New Issue
Block a user