package cabana_test import ( "net/http" "strings" "testing" ) // TestMarkdownPreviewRoute drives POST /markdown/preview through the // assembled router: without credentials the backend guard answers 401, and a // signed-in administrator gets the sanitized rendering with raw script tags // stripped by the renderer. func TestMarkdownPreviewRoute(t *testing.T) { env := newConformEnv(t) anon := env.send(t, http.MethodPost, "/markdown/preview", map[string]string{"markdown": "# Hello"}, false) if anon.Code != http.StatusUnauthorized { t.Fatalf("anonymous status=%d body=%s", anon.Code, anon.Body.String()) } env.loginAs(t, env.login) rec := env.send(t, http.MethodPost, "/markdown/preview", map[string]string{"markdown": "# Hello\n\n"}, true) if rec.Code != http.StatusOK { t.Fatalf("status=%d body=%s", rec.Code, rec.Body.String()) } body := strings.ToLower(rec.Body.String()) if strings.Contains(body, "