refactor: shared escapeHtml util; escape prop-viewer src/alt
This commit is contained in:
@@ -26,4 +26,11 @@ describe('<prop-viewer>', () => {
|
||||
el.querySelector('[data-role=overlay]').click();
|
||||
expect(el.isOpen()).toBe(false);
|
||||
});
|
||||
|
||||
it('escapes a label containing a quote (no attribute break)', () => {
|
||||
el.show('/art/x.png', 'x" onerror="boom');
|
||||
const img = el.querySelector('[data-role=prop-img]');
|
||||
expect(img.getAttribute('alt')).toBe('x" onerror="boom');
|
||||
expect(img.hasAttribute('onerror')).toBe(false);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -0,0 +1,16 @@
|
||||
import { describe, it, expect } from 'vitest';
|
||||
import { escapeHtml } from '../../src/core/escape-html.js';
|
||||
|
||||
describe('escapeHtml', () => {
|
||||
it('escapes the five HTML-significant characters', () => {
|
||||
expect(escapeHtml(`a & b < c > d " e ' f`)).toBe('a & b < c > d " e ' f');
|
||||
});
|
||||
it('replaces & first so entities are not double-escaped', () => {
|
||||
expect(escapeHtml('<')).toBe('<');
|
||||
expect(escapeHtml('<')).toBe('&lt;');
|
||||
});
|
||||
it('coerces null/undefined to empty string', () => {
|
||||
expect(escapeHtml(null)).toBe('');
|
||||
expect(escapeHtml(undefined)).toBe('');
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user