Files
WRNexusJS/packages/ssr/test/ssr.test.ts
T
2026-07-12 15:55:18 +05:30

25 lines
920 B
TypeScript

import { expect, test } from "bun:test";
import { renderDocument } from "../src/index.ts";
test("escapes metadata and script URLs while preserving trusted rendered body", () => {
const html = renderDocument({
meta: { title: '</title><script>alert("x")</script>', description: '" onload="x' },
body: "<main>trusted</main>",
scripts: ['"><script>alert(1)</script>'],
});
expect(html).not.toContain('</title><script>alert("x")</script>');
expect(html).toContain("&lt;/title&gt;");
expect(html).toContain("<main>trusted</main>");
expect(html).not.toContain("<script>alert(1)</script>");
});
test("deduplicates runtime scripts and module preloads", () => {
const html = renderDocument({
meta: { title: "Page" },
body: "",
scripts: ["/app.js", "/app.js"],
});
expect(html.match(/rel="modulepreload"/g)).toHaveLength(1);
expect(html.match(/src="\/app\.js"/g)).toHaveLength(1);
});