Files
EpicNext-Cms/src/lib/sanitize.test.ts
T
openhands 399c047515
CI / check (push) Successful in 1m21s
CI / deploy (push) Successful in 1m25s
fix: harden admin actions, search, sanitization and repo hygiene
- Split approve/dismiss application workflows with distinct audit logs,
  rate-limited guards and real error logging
- Validate article status/date/id input and stop resetting publishedAt
  on every update
- Validate guild updates (state, forum enums, non-empty name) behind
  rate-limited guard
- Fix scheduled-article publishing (ignore NULL dates, set updatedAt,
  type-safe predicates)
- Harden admin search API (LIKE escaping, query cap, per-user
  rate limit, round-robin result cap) and fix search dialog
  abort/res.ok/loading races
- Lock down HTML sanitizer to an allowlist profile and add XSS tests
- Improve mobile nav accessibility (unique id, dialog role, focus
  management, scroll lock, outside close)
- Log swallowed server errors instead of silent catch blocks
- Remove dead eslint config, drop unused dompurify deps, restore knip
  CI step, add Playwright config with smoke spec
2026-09-04 13:04:08 +02:00

38 lines
1.1 KiB
TypeScript

import { describe, expect, it } from "vitest";
import { sanitize } from "./sanitize";
describe("sanitize", () => {
it("returns empty string for nullish input", () => {
expect(sanitize(null)).toBe("");
expect(sanitize(undefined)).toBe("");
expect(sanitize("")).toBe("");
});
it("keeps safe formatting tags", () => {
const out = sanitize("<p>Hello <strong>world</strong></p>");
expect(out).toContain("<strong>world</strong>");
});
it("strips event handlers", () => {
const out = sanitize('<img src="x.gif" onerror="alert(1)">');
expect(out).not.toContain("onerror");
});
it("strips javascript: URLs", () => {
const out = sanitize('<a href="javascript:alert(1)">click</a>');
expect(out).not.toContain("javascript:");
});
it("strips svg onload vectors", () => {
const out = sanitize('<svg onload="alert(1)"><circle r="10"/></svg>');
expect(out).not.toContain("onload");
expect(out).not.toContain("<svg");
});
it("strips script tags", () => {
const out = sanitize("<p>hi</p><script>alert(1)</script>");
expect(out).not.toContain("<script");
expect(out).toContain("hi");
});
});