[verified] feat: add specialized diagram profiles

This commit is contained in:
2026-09-03 19:11:51 +00:00
parent 5146b14d43
commit ced42f02f9
18 changed files with 893 additions and 6 deletions
@@ -0,0 +1,18 @@
import assert from "node:assert/strict";
import test from "node:test";
import { createRunbookHtml } from "./runbook.js";
const GRAPH = { title: "Ops <Runbook>", startId: "start", nodes: [{ id: "start", label: "Is it healthy? </script><img src=x onerror=alert(1)>", choices: [{ label: "No & investigate", target: "check" }] }, { id: "check", label: "Check logs", choices: [{ label: "Retry", target: "start" }] }] };
test("runbook HTML is deterministic, self-contained and escapes malicious labels", () => {
const before = structuredClone(GRAPH); const html = createRunbookHtml(GRAPH);
assert.equal(html, createRunbookHtml(GRAPH)); assert.deepEqual(GRAPH, before);
assert.ok(html.includes("default-src 'none'")); assert.ok(html.includes("Breadcrumb")); assert.ok(html.includes("Back")); assert.ok(html.includes("Restart")); assert.ok(html.includes("keydown"));
assert.ok(html.includes("border-radius:0")); assert.equal(/border-radius:(?!0(?:[;}]))/.test(html), false);
assert.equal(html.includes("</script><img"), false); assert.equal(html.includes("onerror=alert"), false); assert.equal(/(?:src|href)=["']https?:/i.test(html), false);
});
test("runbook rejects empty graphs and unknown targets", () => {
assert.throws(() => createRunbookHtml({ title: "Empty", startId: "x", nodes: [] }), /node/i);
assert.throws(() => createRunbookHtml({ title: "Bad", startId: "a", nodes: [{ id: "a", label: "A", choices: [{ label: "Go", target: "b" }] }] }), /target/i);
});