aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web/web_test.go
diff options
context:
space:
mode:
Diffstat (limited to 'internal/web/web_test.go')
-rw-r--r--internal/web/web_test.go32
1 files changed, 29 insertions, 3 deletions
diff --git a/internal/web/web_test.go b/internal/web/web_test.go
index b803003..48f380e 100644
--- a/internal/web/web_test.go
+++ b/internal/web/web_test.go
@@ -491,15 +491,41 @@ func TestFileMarkdown(t *testing.T) {
if got := fileMarkdown(doc); got != "[notes v2.pdf](/media/6ba7b810-9dad-11d1-80b4-00c04fd430c8)" {
t.Errorf("document should be a link: %q", got)
}
- if got := appendFileMD("", img); got != line+"\n" {
+ if got := appendFile("", img, store.FormatMarkdown); got != line+"\n" {
t.Errorf("empty body: %q", got)
}
- if got := appendFileMD("hello\n", img); got != "hello\n\n"+line+"\n" {
+ if got := appendFile("hello\n", img, store.FormatMarkdown); got != "hello\n\n"+line+"\n" {
t.Errorf("appended: %q", got)
}
- if got := appendFileMD("hello", nil); got != "hello" {
+ if got := appendFile("hello", nil, store.FormatMarkdown); got != "hello" {
t.Errorf("nil file should not change the body: %q", got)
}
+ // HTML mode: tags, with the name escaped
+ img.Filename = `a "cat" <3.png`
+ tag := `<img src="/media/6ba7b810-9dad-11d1-80b4-00c04fd430c8" alt="a &#34;cat&#34; &lt;3.png">`
+ if got := fileHTML(img); got != tag {
+ t.Errorf("image tag: %q", got)
+ }
+ if got := fileHTML(doc); got != `<a href="/media/6ba7b810-9dad-11d1-80b4-00c04fd430c8">notes
+v2.pdf</a>` {
+ t.Errorf("document link: %q", got)
+ }
+ if got := appendFile("<p>hi</p>", img, store.FormatHTML); got != "<p>hi</p>\n\n"+tag+"\n" {
+ t.Errorf("html appended: %q", got)
+ }
+}
+
+func TestRenderBody(t *testing.T) {
+ raw := "**x**\n\n<script>1</script>"
+ if got := renderBody(store.FormatHTML, raw); got != raw {
+ t.Errorf("html must pass through untouched: %q", got)
+ }
+ if got := renderBody(store.FormatMarkdown, raw); !strings.Contains(got, "<strong>x</strong>") || strings.Contains(got, "<script>") {
+ t.Errorf("markdown must be rendered and sanitised: %q", got)
+ }
+ if got := renderBody("", "**x**"); !strings.Contains(got, "<strong>") {
+ t.Errorf("an unset format is markdown: %q", got)
+ }
}
func TestPreviewRendersMarkdown(t *testing.T) {