const renderer = require('../../../modules/rendering/html-security/renderer')
describe('modules/rendering/html-security', () => {
const config = {
safeHTML: true,
allowDrawIoUnsafe: false,
allowIFrames: false
}
it('keeps the slot directives emitted by the tabset renderer', async () => {
const input = 'Tab' +
''
const result = await renderer.init(input, config)
expect(result).toEqual(input)
})
it('strips the value of v-slot:tabs so it cannot be compiled as an expression', async () => {
const input = `Tab`
const result = await renderer.init(input, config)
expect(result).toEqual('Tab')
})
it('strips the value of v-slot:content so it cannot be compiled as an expression', async () => {
const input = `Content
`
const result = await renderer.init(input, config)
expect(result).toEqual('Content
')
})
it('strips the value of v-pre', async () => {
const result = await renderer.init(`
Text
`, config)
expect(result).toEqual('Text
')
})
it('removes any other directive or binding attribute', async () => {
const inputs = [
`Text
`,
`Text
`,
`Text
`,
`Text
`,
`Text
`,
`Text
`
]
for (const input of inputs) {
expect(await renderer.init(input, config)).toEqual('Text
')
}
})
it('leaves regular content attributes untouched', async () => {
const input = 'Link'
const result = await renderer.init(input, config)
expect(result).toEqual(input)
})
it('does not sanitize anything when safeHTML is disabled', async () => {
const input = `Tab`
const result = await renderer.init(input, { ...config, safeHTML: false })
expect(result).toEqual(input)
})
})