diff options
Diffstat (limited to 'internal/web/web_test.go')
| -rw-r--r-- | internal/web/web_test.go | 32 |
1 files changed, 29 insertions, 3 deletions
diff --git a/internal/web/web_test.go b/internal/web/web_test.go index b803003..48f380e 100644 --- a/internal/web/web_test.go +++ b/internal/web/web_test.go @@ -491,15 +491,41 @@ func TestFileMarkdown(t *testing.T) { if got := fileMarkdown(doc); got != "[notes v2.pdf](/media/6ba7b810-9dad-11d1-80b4-00c04fd430c8)" { t.Errorf("document should be a link: %q", got) } - if got := appendFileMD("", img); got != line+"\n" { + if got := appendFile("", img, store.FormatMarkdown); got != line+"\n" { t.Errorf("empty body: %q", got) } - if got := appendFileMD("hello\n", img); got != "hello\n\n"+line+"\n" { + if got := appendFile("hello\n", img, store.FormatMarkdown); got != "hello\n\n"+line+"\n" { t.Errorf("appended: %q", got) } - if got := appendFileMD("hello", nil); got != "hello" { + if got := appendFile("hello", nil, store.FormatMarkdown); got != "hello" { t.Errorf("nil file should not change the body: %q", got) } + // HTML mode: tags, with the name escaped + img.Filename = `a "cat" <3.png` + tag := `<img src="/media/6ba7b810-9dad-11d1-80b4-00c04fd430c8" alt="a "cat" <3.png">` + if got := fileHTML(img); got != tag { + t.Errorf("image tag: %q", got) + } + if got := fileHTML(doc); got != `<a href="/media/6ba7b810-9dad-11d1-80b4-00c04fd430c8">notes +v2.pdf</a>` { + t.Errorf("document link: %q", got) + } + if got := appendFile("<p>hi</p>", img, store.FormatHTML); got != "<p>hi</p>\n\n"+tag+"\n" { + t.Errorf("html appended: %q", got) + } +} + +func TestRenderBody(t *testing.T) { + raw := "**x**\n\n<script>1</script>" + if got := renderBody(store.FormatHTML, raw); got != raw { + t.Errorf("html must pass through untouched: %q", got) + } + if got := renderBody(store.FormatMarkdown, raw); !strings.Contains(got, "<strong>x</strong>") || strings.Contains(got, "<script>") { + t.Errorf("markdown must be rendered and sanitised: %q", got) + } + if got := renderBody("", "**x**"); !strings.Contains(got, "<strong>") { + t.Errorf("an unset format is markdown: %q", got) + } } func TestPreviewRendersMarkdown(t *testing.T) { |
