import assert from 'node:assert/strict'; import { test } from 'node:test'; import { prepareDiagramHtml } from '../src/webviewHtml'; const page = ` `; test('adds one CSP and nonces every inline script', () => { const html = prepareDiagramHtml(page, { cspSource: 'vscode-resource:', nonce: 'N0NCE', theme: 'light' }); const csps = html.match(/Content-Security-Policy/g) ?? []; assert.equal(csps.length, 1); assert.match(html, /script-src ('|')nonce-N0NCE/); const scripts = html.match(/]*>/g) ?? []; assert.equal(scripts.length, 4, 'bridge plus the three page scripts'); for (const tag of scripts) assert.match(tag, /nonce="N0NCE"/); }); test('bridge runs before the page scripts and pins the theme', () => { const html = prepareDiagramHtml(page, { cspSource: 'x', nonce: 'n', theme: 'dark', hash: '#focus=api' }); const bridge = html.indexOf('acquireVsCodeApi'); assert.ok(bridge > 0 && bridge < html.indexOf('var a = 1')); assert.match(html, /"theme":"dark"/); assert.match(html, /"hash":"#focus=api"/); }); test('embedded config cannot close the script element', () => { const html = prepareDiagramHtml(page, { cspSource: 'x', nonce: 'n', theme: undefined, notice: { kind: 'warning', text: '' }, }); assert.ok(!html.includes('