[verified] feat: add specialized diagram profiles
This commit is contained in:
@@ -0,0 +1,18 @@
|
||||
import assert from "node:assert/strict";
|
||||
import test from "node:test";
|
||||
import { createRunbookHtml } from "./runbook.js";
|
||||
|
||||
const GRAPH = { title: "Ops <Runbook>", startId: "start", nodes: [{ id: "start", label: "Is it healthy? </script><img src=x onerror=alert(1)>", choices: [{ label: "No & investigate", target: "check" }] }, { id: "check", label: "Check logs", choices: [{ label: "Retry", target: "start" }] }] };
|
||||
|
||||
test("runbook HTML is deterministic, self-contained and escapes malicious labels", () => {
|
||||
const before = structuredClone(GRAPH); const html = createRunbookHtml(GRAPH);
|
||||
assert.equal(html, createRunbookHtml(GRAPH)); assert.deepEqual(GRAPH, before);
|
||||
assert.ok(html.includes("default-src 'none'")); assert.ok(html.includes("Breadcrumb")); assert.ok(html.includes("Back")); assert.ok(html.includes("Restart")); assert.ok(html.includes("keydown"));
|
||||
assert.ok(html.includes("border-radius:0")); assert.equal(/border-radius:(?!0(?:[;}]))/.test(html), false);
|
||||
assert.equal(html.includes("</script><img"), false); assert.equal(html.includes("onerror=alert"), false); assert.equal(/(?:src|href)=["']https?:/i.test(html), false);
|
||||
});
|
||||
|
||||
test("runbook rejects empty graphs and unknown targets", () => {
|
||||
assert.throws(() => createRunbookHtml({ title: "Empty", startId: "x", nodes: [] }), /node/i);
|
||||
assert.throws(() => createRunbookHtml({ title: "Bad", startId: "a", nodes: [{ id: "a", label: "A", choices: [{ label: "Go", target: "b" }] }] }), /target/i);
|
||||
});
|
||||
Reference in New Issue
Block a user