41 lines
1.5 KiB
TypeScript
41 lines
1.5 KiB
TypeScript
import assert from "node:assert/strict";
|
|
import test from "node:test";
|
|
|
|
import type { DiagramIRV2 } from "../../model/diagram-ir.js";
|
|
import { diagramIRToMermaid, diagramIRToStructuredMarkdown } from "./reverse.js";
|
|
|
|
const IR: DiagramIRV2 = {
|
|
version: 2,
|
|
title: "Platform",
|
|
pages: [{
|
|
id: "system", title: "System",
|
|
nodes: [
|
|
{ id: "a", label: "Client" },
|
|
{ id: "b", label: "API \"danger\"]\n%%{init: {}}%% <script>alert(1)</script> [click](javascript:alert(1))" },
|
|
],
|
|
edges: [{ id: "call", source: "a", target: "b", label: "calls | inject" }],
|
|
}],
|
|
};
|
|
|
|
test("reverse Mermaid flowchart is deterministic and escapes untrusted labels", () => {
|
|
const output = diagramIRToMermaid(IR);
|
|
assert.equal(output, diagramIRToMermaid(IR));
|
|
assert.match(output, /^flowchart LR/m);
|
|
assert.match(output, /n0\["Client"\]/);
|
|
assert.match(output, /n0 -->\|"calls | inject"\| n1/);
|
|
assert.doesNotMatch(output, /<script>|%%\{init|danger"\]/);
|
|
assert.match(output, /%%/);
|
|
});
|
|
|
|
test("reverse Markdown explains pages, nodes, and flows without executable HTML or broken tables", () => {
|
|
const output = diagramIRToStructuredMarkdown(IR);
|
|
assert.equal(output, diagramIRToStructuredMarkdown(IR));
|
|
assert.match(output, /## System/);
|
|
assert.match(output, /### Nodes/);
|
|
assert.match(output, /### Flows/);
|
|
assert.match(output, /calls \\| inject/);
|
|
assert.doesNotMatch(output, /<script>/);
|
|
assert.doesNotMatch(output, /\]\(javascript:/);
|
|
assert.match(output, /<script>/);
|
|
});
|