Skip to content

Commit 3f99d52

Browse files
committed
test(notes): 钉住 URL 消毒只放行内部锚点
1 parent c0ce993 commit 3f99d52

1 file changed

Lines changed: 6 additions & 6 deletions

File tree

‎app/src/components/NoteMarkdown.test.tsx‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -144,18 +144,18 @@ describe("NoteMarkdown [[ts:ms]] 接上毫秒(批 6 T26)", () => {
144144
}
145145
});
146146

147-
it("④ 非 ts 链接不受影响:仍渲染 <a href>,点击不触发任何会话回调", () => {
147+
it("④ 普通链接不受影响:hash/https 仍渲染 <a href>、javascript: 仍被清空,点击不触发会话回调", () => {
148148
const at = vi.fn();
149149
const plain = vi.fn();
150-
// 用同页 hash 链接做反例点击(jsdom 里外链点击会打印 navigation 未实现告警,噪声无益)
151150
const { container } = render(
152-
<NoteMarkdown note={note("[普通链接](#section)")} searchQuery="" onTaskToggle={noop} onOpenSession={plain} onOpenSessionAt={at} onImageOpen={noop} />,
151+
<NoteMarkdown note={note("[本页](#section) [外链](https://example.com) [坏](javascript:alert(1))")} searchQuery="" onTaskToggle={noop} onOpenSession={plain} onOpenSessionAt={at} onImageOpen={noop} />,
153152
);
154-
const anchor = container.querySelector("a");
155-
expect(anchor?.getAttribute("href")).toBe("#section");
153+
const anchors = [...container.querySelectorAll("a")];
154+
// 两侧自证:普通 URL 逐字保留(https)· 危险协议仍被默认消毒器清空(T26 只放行 `[[ts:ms]]` 一种形态)
155+
expect(anchors.map((a) => a.getAttribute("href"))).toEqual(["#section", "https://example.com", ""]);
156156
expect(container.querySelectorAll('span[title*="跳转到会话"]'), "普通链接被误渲染成回链芯片").toHaveLength(0);
157157

158-
fireEvent.click(anchor as HTMLAnchorElement);
158+
fireEvent.click(anchors[0]); // 同页 hash(jsdom 里外链点击会打印 navigation 未实现告警,噪声无益)
159159

160160
expect(at).toHaveBeenCalledTimes(0);
161161
expect(plain).toHaveBeenCalledTimes(0);

0 commit comments

Comments
 (0)