[READ-ONLY] Mirror of https://github.com/darccio/zas. Most simple static website generator in Golang.
go static-site-generation static-site-generator
Something went wrong. Try again.
zas codeblock_test.go
3.3 kB · 85 lines
1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586package zas
import ( "strings" "testing")
// renderMarkdown used to run goldmark's converter output through// html.UnescapeString before handing it to the HTML5 parser in// parseAndReplace. Goldmark escapes code block contents on the way out, so// that unescape turned HTML entities inside a fenced or indented code block// back into raw markup bytes right before they were re-parsed as HTML -// corrupting <, >, and & in code samples, and turning a literal <script>// tag typed inside a code fence into a live, executing script. These tests// drive the full Generator.Run pipeline (not just markdownConverter, which// cannot observe this bug) against testdata/site/codeblocks.md.
func TestGenerateEscapesHTMLInFencedCodeBlock(t *testing.T) { newTestSite(t, "site") if err := generate(t); err != nil { t.Fatalf("generate() error = %v, want nil", err) } out := readDeploy(t, "codeblocks.html") if !strings.Contains(out, "<b>hi</b>") { t.Fatalf("codeblocks.html = %q, want the fenced <b>hi</b> sample left escaped", out) } if strings.Contains(out, "<b>hi</b>") { t.Fatalf("codeblocks.html = %q, want no real <b> element from the code sample", out) }}
func TestGenerateDoesNotExecuteScriptInFencedCodeBlock(t *testing.T) { newTestSite(t, "site") if err := generate(t); err != nil { t.Fatalf("generate() error = %v, want nil", err) } out := readDeploy(t, "codeblocks.html") if !strings.Contains(out, "<script>alert(1)</script>") { t.Fatalf("codeblocks.html = %q, want the fenced <script> sample left escaped", out) } if strings.Contains(out, "<script>alert(1)</script>") { t.Fatalf("codeblocks.html = %q, want no live <script> element from the code sample", out) }}
func TestGenerateKeepsDoubleEscapedEntitiesInCodeBlock(t *testing.T) { newTestSite(t, "site") if err := generate(t); err != nil { t.Fatalf("generate() error = %v, want nil", err) } out := readDeploy(t, "codeblocks.html") want := `<pre><code class="language-text">&lt;script&gt;` if !strings.Contains(out, want) { t.Fatalf("codeblocks.html = %q, want it to contain %q (literal <script> typed in source keeping its full escaping)", out, want) } degraded := `<pre><code class="language-text"><script>` if strings.Contains(out, degraded) { t.Fatalf("codeblocks.html = %q, the language-text block lost a level of escaping (want &lt;..&gt;, got <..>)", out) }}
func TestGenerateEscapesHTMLInIndentedCodeBlock(t *testing.T) { newTestSite(t, "site") if err := generate(t); err != nil { t.Fatalf("generate() error = %v, want nil", err) } out := readDeploy(t, "codeblocks.html") if !strings.Contains(out, "<b>indented</b>") { t.Fatalf("codeblocks.html = %q, want the indented <b>indented</b> sample left escaped", out) } if strings.Contains(out, "<b>indented</b>") { t.Fatalf("codeblocks.html = %q, want no real <b> element from the indented sample", out) }}
func TestGenerateFencedCodeBlockGetsLanguageClass(t *testing.T) { newTestSite(t, "site") if err := generate(t); err != nil { t.Fatalf("generate() error = %v, want nil", err) } out := readDeploy(t, "codeblocks.html") if !strings.Contains(out, `<pre><code class="language-html">`) { t.Fatalf("codeblocks.html = %q, want a fenced code block with a language-html class", out) }}