zz_escape_test.gno
1.23 Kb · 30 lines
1package linktree
2
3import (
4 "strings"
5 "testing"
6
7 "gno.land/p/nt/testutils/v0"
8 "gno.land/p/nt/uassert/v0"
9)
10
11// The bio and a label are escaped, and a URL that could break out of its
12// link destination, or is not http(s), is refused when it is written.
13func TestProfileFieldsAreEscapedAndURLsChecked(cur realm, t *testing.T) {
14 who := testutils.TestAddress("escaper")
15 testing.SetRealm(testing.NewUserRealm(who))
16 SetBio(cross(cur), "[claim](https://evil.example)")
17 AddLink(cross(cur), "[claim](https://evil.example)", "https://ok.example/path")
18 page := Render(who.String())
19 uassert.False(t, strings.Contains(page, "[claim](https://evil.example)"), page)
20 uassert.AbortsContains(t, cur, "url must be http", func() { AddLink(cross(cur), "x", "javascript:alert(1)") })
21 uassert.AbortsContains(t, cur, "url must be http", func() { AddLink(cross(cur), "x", "https://a.example) [evil](https://b.example") })
22}
23
24// A path that names nothing is echoed back on the not-found page. It is the
25// visitor's text, so a backtick in it must not close a code span and let a
26// link through.
27func TestNotFoundPathIsEscaped(t *testing.T) {
28 out := Render("x` [claim](https://evil.example) `")
29 uassert.False(t, strings.Contains(out, "[claim](https://evil.example)"), out)
30}