zz_escape_test.gno
0.97 Kb · 28 lines
1package vault
2
3import (
4 "strings"
5 "testing"
6
7 "gno.land/p/nt/testutils/v0"
8 "gno.land/p/nt/uassert/v0"
9)
10
11// A key and a value are the owner's text, written into table cells: a pipe
12// must not open a column and a link must not go live.
13func TestKeysAndValuesAreTableSafe(cur realm, t *testing.T) {
14 who := testutils.TestAddress("escaper")
15 testing.SetRealm(testing.NewUserRealm(who))
16 Set(cross(cur), "k | [claim](https://evil.example)", "[claim](https://evil.example)")
17 page := Render(who.String())
18 uassert.False(t, strings.Contains(page, "[claim](https://evil.example)"), page)
19 uassert.False(t, strings.Contains(page, "| k | "), page)
20}
21
22// A path that names nothing is echoed back on the not-found page. It is the
23// visitor's text, so a backtick in it must not close a code span and let a
24// link through.
25func TestNotFoundPathIsEscaped(t *testing.T) {
26 out := Render("x` [claim](https://evil.example) `")
27 uassert.False(t, strings.Contains(out, "[claim](https://evil.example)"), out)
28}