Add 22 test files covering imager, soundtracks, browser-headers, source-keys (figure/pet/effect), effect-source, plus catalog-translations, catalog-layouts, client-translation-files, translations-utils, and various admin/services/helpers modules. Total test count increases by 120+.
33 lines
1.0 KiB
TypeScript
33 lines
1.0 KiB
TypeScript
import { describe, expect, it } from "vitest";
|
|
import { tryRemoveLocalPhotoFile } from "./photo-files";
|
|
|
|
describe("tryRemoveLocalPhotoFile", () => {
|
|
it("returns false for empty or nullish urls", async () => {
|
|
expect(await tryRemoveLocalPhotoFile("")).toBe(false);
|
|
expect(await tryRemoveLocalPhotoFile(" ")).toBe(false);
|
|
});
|
|
|
|
it("returns false for external urls not on this app origin", async () => {
|
|
expect(
|
|
await tryRemoveLocalPhotoFile("https://evil.example.com/photos/x.png"),
|
|
).toBe(false);
|
|
});
|
|
|
|
it("returns false for urls without a leading slash", async () => {
|
|
expect(await tryRemoveLocalPhotoFile("photos/x.png")).toBe(false);
|
|
});
|
|
|
|
it("blocks path traversal", async () => {
|
|
expect(await tryRemoveLocalPhotoFile("/../../etc/passwd")).toBe(false);
|
|
expect(await tryRemoveLocalPhotoFile("/photos/..%2f..%2fetc/passwd")).toBe(
|
|
false,
|
|
);
|
|
});
|
|
|
|
it("returns false when the target file does not exist", async () => {
|
|
expect(
|
|
await tryRemoveLocalPhotoFile("/photos/definitely-missing.png"),
|
|
).toBe(false);
|
|
});
|
|
});
|