refactor: shared escapeHtml util; escape prop-viewer src/alt

This commit is contained in:
2026-07-20 15:35:57 +01:00
parent 9a5e4c4ce4
commit 5bdeef654e
5 changed files with 35 additions and 10 deletions
+7
View File
@@ -26,4 +26,11 @@ describe('<prop-viewer>', () => {
el.querySelector('[data-role=overlay]').click();
expect(el.isOpen()).toBe(false);
});
it('escapes a label containing a quote (no attribute break)', () => {
el.show('/art/x.png', 'x" onerror="boom');
const img = el.querySelector('[data-role=prop-img]');
expect(img.getAttribute('alt')).toBe('x" onerror="boom');
expect(img.hasAttribute('onerror')).toBe(false);
});
});
+16
View File
@@ -0,0 +1,16 @@
import { describe, it, expect } from 'vitest';
import { escapeHtml } from '../../src/core/escape-html.js';
describe('escapeHtml', () => {
it('escapes the five HTML-significant characters', () => {
expect(escapeHtml(`a & b < c > d " e ' f`)).toBe('a &amp; b &lt; c &gt; d &quot; e &#39; f');
});
it('replaces & first so entities are not double-escaped', () => {
expect(escapeHtml('<')).toBe('&lt;');
expect(escapeHtml('&lt;')).toBe('&amp;lt;');
});
it('coerces null/undefined to empty string', () => {
expect(escapeHtml(null)).toBe('');
expect(escapeHtml(undefined)).toBe('');
});
});