Files
summercms/admin/tests/app/router.test.ts
Jakub Zych 1c2a66df45 test(10-05): bring every SPA module, composable and component under Vitest
- 41 unit and component suites under admin/tests/{app,state,shell,list,form,relation,views,ui}
  covering states and a11y roles; every src module is imported by a test
- typed fixture helper assigns each JSON fixture to its generated OpenAPI type
- fix: iconFor ignores inherited object members such as "constructor"
- fix: field controls import ./control instead of the registry (import cycle
  left a renderer unregistered depending on module load order)
- fix: dropdown shows the placeholder for an unknown stored value next to an emptyOption
- fix: list announces a failed schema load even when the rows arrive after it
- tailwind no longer scans admin/tests; boardwalk/dist rebuilt
2026-09-27 17:53:57 +02:00

96 lines
3.6 KiB
TypeScript

import { beforeEach, describe, expect, it } from 'vitest'
import { createMemoryHistory } from 'vue-router'
import { createAdminRouter, safeRedirect } from '../../src/app/router'
import { setNavigation } from '../../src/state/useNavigation'
import { navigationFixture } from '../fixtures/typed'
import { resetState, routerAt, signIn } from '../helpers'
beforeEach(() => {
resetState()
})
describe('safeRedirect', () => {
it('accepts in-app paths with exactly one leading slash', () => {
expect(safeRedirect('/acme/demo/widgets')).toBe('/acme/demo/widgets')
expect(safeRedirect('/acme/demo/widgets/1?tab=2#x')).toBe('/acme/demo/widgets/1?tab=2#x')
expect(safeRedirect('/')).toBe('/')
})
it.each([
['protocol-relative', '//evil.example/x'],
['backslash protocol-relative', '/\\evil.example'],
['absolute http', 'http://evil.example/'],
['absolute https', 'https://evil.example/'],
['javascript', 'javascript:alert(1)'],
['relative', 'acme/demo'],
['empty', ''],
])('rejects a %s value', (_label, value) => {
expect(safeRedirect(value)).toBeNull()
})
it('rejects non-string values', () => {
expect(safeRedirect(undefined)).toBeNull()
expect(safeRedirect(null)).toBeNull()
expect(safeRedirect(['/a'])).toBeNull()
expect(safeRedirect(1)).toBeNull()
})
})
describe('route guard', () => {
it('sends a visitor without a session to login with the requested path', async () => {
const router = await routerAt('/acme/demo/widgets/3?x=1')
expect(router.currentRoute.value.name).toBe('login')
expect(router.currentRoute.value.query.redirect).toBe('/acme/demo/widgets/3?x=1')
})
it('lets a visitor open the login screen', async () => {
const router = await routerAt('/login')
expect(router.currentRoute.value.name).toBe('login')
})
it('moves a signed-in admin away from login to a safe redirect', async () => {
await signIn()
const router = await routerAt('/login?redirect=/acme/demo/gadgets')
expect(router.currentRoute.value.fullPath).toBe('/acme/demo/gadgets')
})
it.each(['//evil.example/x', 'https://evil.example/', '/\\evil'])(
'ignores the unsafe redirect %j and goes home',
async (redirect) => {
await signIn()
setNavigation(navigationFixture.data)
const router = createAdminRouter(createMemoryHistory())
await router.push({ path: '/login', query: { redirect } })
expect(router.currentRoute.value.fullPath).toBe('/acme/demo/widgets')
},
)
it('lands home on the first permitted controller, or on the empty page without navigation', async () => {
await signIn()
setNavigation(navigationFixture.data)
expect((await routerAt('/')).currentRoute.value.fullPath).toBe('/acme/demo/widgets')
setNavigation([])
const empty = await routerAt('/')
expect(empty.currentRoute.value.name).toBe('home')
})
it('names the list, create, record, settings and not-found routes', async () => {
await signIn()
const cases: Array<[string, string]> = [
['/acme/demo/widgets', 'list'],
['/acme/demo/widgets/create', 'create'],
['/acme/demo/widgets/12', 'record'],
['/acme/demo/widgets/abc', 'not-found'],
['/settings', 'settings'],
['/settings/mail', 'settings-form'],
['/nowhere', 'not-found'],
]
for (const [path, name] of cases) {
const router = await routerAt(path)
expect(router.currentRoute.value.name, path).toBe(name)
expect(router.currentRoute.value.meta.shell, path).toBe(true)
}
expect((await routerAt('/acme/demo/widgets/12')).currentRoute.value.params.id).toBe('12')
})
})