[verified] feat: add diagram toolbox capabilities
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
import assert from "node:assert/strict";
|
||||
import test from "node:test";
|
||||
|
||||
import type { DiagramIRV2 } from "../../model/diagram-ir.js";
|
||||
import { diagramIRToMermaid, diagramIRToStructuredMarkdown } from "./reverse.js";
|
||||
|
||||
const IR: DiagramIRV2 = {
|
||||
version: 2,
|
||||
title: "Platform",
|
||||
pages: [{
|
||||
id: "system", title: "System",
|
||||
nodes: [
|
||||
{ id: "a", label: "Client" },
|
||||
{ id: "b", label: "API \"danger\"]\n%%{init: {}}%% <script>alert(1)</script> [click](javascript:alert(1))" },
|
||||
],
|
||||
edges: [{ id: "call", source: "a", target: "b", label: "calls | inject" }],
|
||||
}],
|
||||
};
|
||||
|
||||
test("reverse Mermaid flowchart is deterministic and escapes untrusted labels", () => {
|
||||
const output = diagramIRToMermaid(IR);
|
||||
assert.equal(output, diagramIRToMermaid(IR));
|
||||
assert.match(output, /^flowchart LR/m);
|
||||
assert.match(output, /n0\["Client"\]/);
|
||||
assert.match(output, /n0 -->\|"calls | inject"\| n1/);
|
||||
assert.doesNotMatch(output, /<script>|%%\{init|danger"\]/);
|
||||
assert.match(output, /%%/);
|
||||
});
|
||||
|
||||
test("reverse Markdown explains pages, nodes, and flows without executable HTML or broken tables", () => {
|
||||
const output = diagramIRToStructuredMarkdown(IR);
|
||||
assert.equal(output, diagramIRToStructuredMarkdown(IR));
|
||||
assert.match(output, /## System/);
|
||||
assert.match(output, /### Nodes/);
|
||||
assert.match(output, /### Flows/);
|
||||
assert.match(output, /calls \\| inject/);
|
||||
assert.doesNotMatch(output, /<script>/);
|
||||
assert.doesNotMatch(output, /\]\(javascript:/);
|
||||
assert.match(output, /<script>/);
|
||||
});
|
||||
Reference in New Issue
Block a user