X-Git-Url: http://git.vanrenterghem.biz/git.ikiwiki.info.git/blobdiff_plain/d7e0c035e55e8b47a9ea7e993c9332a7ce9930e1..883880b46ddc0d650f70bd6ca2a22539ff78f1b6:/t/htmlize.t?ds=sidebyside diff --git a/t/htmlize.t b/t/htmlize.t index edf357010..1569c8dcf 100755 --- a/t/htmlize.t +++ b/t/htmlize.t @@ -1,7 +1,7 @@ #!/usr/bin/perl use warnings; use strict; -use Test::More tests => 26; +use Test::More tests => 31; use Encode; BEGIN { use_ok("IkiWiki"); } @@ -12,22 +12,19 @@ $config{srcdir}=$config{destdir}="/dev/null"; IkiWiki::loadplugins(); IkiWiki::checkconfig(); -is(IkiWiki::htmlize("foo", "mdwn", "foo\n\nbar\n"), "<p>foo</p>\n\n<p>bar</p>\n", +is(IkiWiki::htmlize("foo", "foo", "mdwn", "foo\n\nbar\n"), "<p>foo</p>\n\n<p>bar</p>\n", "basic"); -is(IkiWiki::htmlize("foo", "mdwn", readfile("t/test1.mdwn")), - Encode::decode_utf8(qq{<p><img src="../images/o.jpg" alt="o" title="ó" />\nóóóóó</p>\n}), - "utf8; bug #373203"); -ok(IkiWiki::htmlize("foo", "mdwn", readfile("t/test2.mdwn")), +my $val=Encode::encode_utf8(IkiWiki::htmlize("foo", "foo", "mdwn", readfile("t/test1.mdwn"))); +ok($val =~/ó/ && $val =~/óóóóó/, "utf8; bug #373203"); +ok(IkiWiki::htmlize("foo", "foo", "mdwn", readfile("t/test2.mdwn")), "this file crashes markdown if it's fed in as decoded utf-8"); sub gotcha { - my $html=IkiWiki::htmlize("foo", "mdwn", shift); + my $html=IkiWiki::htmlize("foo", "foo", "mdwn", shift); return $html =~ /GOTCHA/; } ok(!gotcha(q{<a href="javascript:alert('GOTCHA')">click me</a>}), "javascript url"); -ok(!gotcha(q{<a href="javascript:alert('GOTCHA')">click me</a>}), - "partially encoded javascript url"); ok(!gotcha(q{<a href="jscript:alert('GOTCHA')">click me</a>}), "jscript url"); ok(!gotcha(q{<a href="vbscript:alert('GOTCHA')">click me</a>}), @@ -46,25 +43,43 @@ ok(!gotcha(q{<video poster="javascript:alert('GOTCHA')" href="foo.avi">foo</vide "video poster with javascript"); ok(!gotcha(q{<span style="background: url(javascript:window.location=GOTCHA)">a</span>}), "CSS script test"); -ok(! gotcha(q{<img src="data:text/javascript:GOTCHA">}), +ok(! gotcha(q{<img src="data:text/javascript;GOTCHA">}), "data:text/javascript (jeez!)"); -ok(gotcha(q{<img src="data:text/png:GOTCHA">}), "data:text/png"); -ok(gotcha(q{<img src="data:text/gif:GOTCHA">}), "data:text/gif"); -ok(gotcha(q{<img src="data:text/jpeg:GOTCHA">}), "data:text/jpeg"); +ok(gotcha(q{<img src="">}), "data:image/png"); +ok(gotcha(q{<img src="">}), "data:image/gif"); +ok(gotcha(q{<img src="">}), "data:image/jpeg"); ok(gotcha(q{<p>javascript:alert('GOTCHA')</p>}), "not javascript AFAIK (but perhaps some web browser would like to be perverse and assume it is?)"); ok(gotcha(q{<img src="javascript.png?GOTCHA">}), "not javascript"); ok(gotcha(q{<a href="javascript.png?GOTCHA">foo</a>}), "not javascript"); -is(IkiWiki::htmlize("foo", "mdwn", +is(IkiWiki::htmlize("foo", "foo", "mdwn", q{<img alt="foo" src="foo.gif">}), q{<img alt="foo" src="foo.gif">}, "img with alt tag allowed"); -is(IkiWiki::htmlize("foo", "mdwn", +is(IkiWiki::htmlize("foo", "foo", "mdwn", q{<a href="http://google.com/">}), q{<a href="http://google.com/">}, "absolute url allowed"); -is(IkiWiki::htmlize("foo", "mdwn", +is(IkiWiki::htmlize("foo", "foo", "mdwn", q{<a href="foo.html">}), q{<a href="foo.html">}, "relative url allowed"); -is(IkiWiki::htmlize("foo", "mdwn", +is(IkiWiki::htmlize("foo", "foo", "mdwn", q{<span class="foo">bar</span>}), q{<span class="foo">bar</span>}, "class attribute allowed"); +is(IkiWiki::htmlize("foo", "foo", "mdwn", + q{<a href="aaa#foo">}), + q{<a href="aaa#foo">}, "simple anchor allowed"); +is(IkiWiki::htmlize("foo", "foo", "mdwn", + q{<a href="aaa#foo:bar">}), + q{<a href="aaa#foo:bar">}, "colon allowed in anchor"); +is(IkiWiki::htmlize("foo", "foo", "mdwn", + q{<a href="aaa?foo:bar">}), + q{<a href="aaa?foo:bar">}, "colon allowed in query string"); +is(IkiWiki::htmlize("foo", "foo", "mdwn", + q{<a href="foo:bar">}), + q{<a>}, "unknown protocol blocked"); +is(IkiWiki::htmlize("foo", "foo", "mdwn", + q{<a href="#foo">}), + q{<a href="#foo">}, "simple relative anchor allowed"); +is(IkiWiki::htmlize("foo", "foo", "mdwn", + q{<a href="#foo:bar">}), + q{<a href="#foo:bar">}, "colon in simple relative anchor allowed");