test(14.2.1-04): add ML, markdown, resolver, and SPA test matrices
Prove nested ML writes, unsafe markdown rejection, request-locale isolation, and generated FormView types. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
40
modules/cabana/markdown_test.go
Normal file
40
modules/cabana/markdown_test.go
Normal file
@@ -0,0 +1,40 @@
|
||||
package cabana
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestMarkdownRejectsUnsafeHTML(t *testing.T) {
|
||||
if html, err := RenderMarkdown("# Hello"); err != nil || !strings.Contains(html, "<h1>") {
|
||||
t.Fatalf("safe markdown: html=%s err=%v", html, err)
|
||||
}
|
||||
|
||||
cases := []struct {
|
||||
name string
|
||||
src string
|
||||
needle string
|
||||
}{
|
||||
{"script", "<script>alert(1)</script>", "<script"},
|
||||
{"iframe", `<iframe src="https://evil.test"></iframe>`, "<iframe"},
|
||||
{"event", `<img src=x onerror="alert(1)">`, "onerror"},
|
||||
{"javascript", "[x](javascript:alert(1))", "javascript:"},
|
||||
{"vbscript", "[x](vbscript:msgbox(1))", "vbscript:"},
|
||||
{"data", "[x](data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==)", "data:"},
|
||||
}
|
||||
for _, tc := range cases {
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
html, err := RenderMarkdown(tc.src)
|
||||
if err == nil && strings.Contains(strings.ToLower(html), tc.needle) {
|
||||
t.Fatalf("unsafe HTML survived: %s", html)
|
||||
}
|
||||
unchecked, convErr := renderMarkdownUnchecked(tc.src)
|
||||
if convErr != nil {
|
||||
t.Fatal(convErr)
|
||||
}
|
||||
if strings.Contains(strings.ToLower(unchecked), tc.needle) && err == nil {
|
||||
t.Fatalf("RenderMarkdown accepted %s: %s", tc.name, html)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user