Something went wrong. Try again.
My website. cameron.stream
Something went wrong. Try again.
TypeScript
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384import assert from "node:assert/strict";import test from "node:test";import { renderMarkdown } from "./markdown.ts";
test("renders inline and display LaTeX as native MathML", async () => { const html = await renderMarkdown(String.raw`Inline $x^2$.
$$g(s) = \frac{1}{Z}p(s)\Phi(s)$$`);
assert.equal((html.match(/<math\b/g) ?? []).length, 2); assert.equal((html.match(/display="block"/g) ?? []).length, 1); assert.match(html, /<annotation encoding="application\/x-tex">x\^2<\/annotation>/); assert.doesNotMatch(html, /\$\$/);});
test("does not interpret ordinary currency as inline math", async () => { const html = await renderMarkdown("Costs range from $5 to $10.");
assert.equal(html.trim(), "<p>Costs range from $5 to $10.</p>"); assert.doesNotMatch(html, /<math\b/);});
test("renders defined footnotes as linked notes", async () => { const html = await renderMarkdown(`A statement[^note].
[^note]: Supporting detail.`);
assert.match(html, /<sup><a id="footnote-ref-note" href="#footnote-note"/); assert.match(html, /<section class="footnotes" data-footnotes>/); assert.match(html, /<li id="footnote-note">/); assert.match(html, /Supporting detail\./);});
test("safe Markdown mode escapes arbitrary HTML, SVG, and scripts", async () => { const html = await renderMarkdown( `<script>alert("x")</script>\n\n<svg onload="alert(1)"><circle /></svg>\n\n<div data-owned="false">text</div>`, { allowRawHtml: false }, );
assert.doesNotMatch(html, /<(?:script|svg|circle|div)\b/i); assert.match(html, /<script>alert\("x"\)<\/script>/); assert.match(html, /<svg onload="alert\(1\)">/); assert.match(html, /<div data-owned="false">text<\/div>/);});
test("safe Markdown mode keeps HTML examples inert inside code fences", async () => { const html = await renderMarkdown( "```html\n<script>alert('x')</script>\n```", { allowRawHtml: false }, );
assert.doesNotMatch(html, /<script>/); assert.match(html, /</); assert.match(html, />script</); assert.match(html, /<pre/);});
test("safe Markdown mode renders inline formatting inside link labels", async () => { const html = await renderMarkdown( "[*An Economy of AI Agents*](https://example.com/economy) [**blocked label**](javascript:alert(1))", { allowRawHtml: false }, );
assert.equal( html, '<p><a href="https://example.com/economy"><em>An Economy of AI Agents</em></a> <strong>blocked label</strong></p>\n', ); assert.doesNotMatch(html, /\*An Economy|javascript:/);});
test("safe Markdown mode denies executable link and image protocols", async () => { const html = await renderMarkdown( "[run](javascript:alert(1)) [encoded](javascript:alert(1))  [slash](\\\\evil.example/path) [encoded-slash](\\evil.example/path)  [source](https://example.com/) [local](/knowledge/example)", { allowRawHtml: false }, );
assert.doesNotMatch(html, /javascript:|data:image|evil\.example|<img/i); assert.match(html, /<p>run encoded payload slash encoded-slash slash-image /); assert.match(html, /href="https:\/\/example\.com\/"/); assert.match(html, /href="\/knowledge\/example"/);});