fix(admin): render markdown preview from server-sanitized HTML
- MarkdownField posts the source to POST /markdown/preview when Preview opens and again 300 ms after a change while open; stale answers dropped - the pane binds only data.html of a 2xx answer; a refusal is a text notice - mlmarkdown previews the active locale and follows a locale switch - .summer-markdown style kit restores headings, lists, code and tables - vitest coverage, forms.md and rebuilt modules/boardwalk/dist
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
import { afterEach, beforeEach, describe, expect, it } from 'vitest'
|
||||
import { enableAutoUnmount, mount } from '@vue/test-utils'
|
||||
import { enableAutoUnmount, flushPromises, mount } from '@vue/test-utils'
|
||||
import { ref } from 'vue'
|
||||
import type { FormField } from '../../src/api/types'
|
||||
import MarkdownField from '../../src/components/form/fields/MarkdownField.vue'
|
||||
@@ -8,7 +8,7 @@ import MLTextField from '../../src/components/form/fields/MLTextField.vue'
|
||||
import { FORM_ENABLED_LOCALES } from '../../src/components/form/formContext'
|
||||
import { editablePayload, initialValues, mergeMLValue } from '../../src/components/form/formState'
|
||||
import { isRegistered, rendererFor } from '../../src/components/form/registry'
|
||||
import { resetState } from '../helpers'
|
||||
import { API, mockApi, resetState } from '../helpers'
|
||||
|
||||
function field(type: string, name = 'title'): FormField {
|
||||
return { name, label: 'Title', type } as FormField
|
||||
@@ -126,6 +126,7 @@ describe('ML field registry and nested save body', () => {
|
||||
})
|
||||
|
||||
it('does not execute raw HTML in the markdown preview', async () => {
|
||||
mockApi({ [`POST ${API}/markdown/preview`]: { body: { data: { html: '<p><!-- raw HTML omitted --></p>\n' }, meta: {} } } })
|
||||
const wrapper = mount(MarkdownField, {
|
||||
props: {
|
||||
field: field('markdown', 'body'),
|
||||
@@ -135,10 +136,10 @@ describe('ML field registry and nested save body', () => {
|
||||
attachTo: document.body,
|
||||
})
|
||||
await wrapper.find('[data-markdown-preview]').trigger('click')
|
||||
await flushPromises()
|
||||
expect(wrapper.find('script').exists()).toBe(false)
|
||||
expect(wrapper.find('img').exists()).toBe(false)
|
||||
expect((window as unknown as { __ml_xss?: number }).__ml_xss).toBeUndefined()
|
||||
expect(wrapper.find('[data-markdown-preview-pane]').text()).toContain('<script>')
|
||||
})
|
||||
|
||||
it('seeds empty maps and lists every enabled locale on create', () => {
|
||||
|
||||
Reference in New Issue
Block a user