Files
gitea/web_src/js/markup/render-iframe.test.ts
T
61be9fcdfa chore: update eslint and stylelint configs and re-sync modern-normalize (#38982)
- update the vendored `modern-normalize` to v3.0.1
- require descriptions for lint disables in TS and CSS, same as we
already have in Go.
- disable core rules covered by `regexp/*` and `unicorn/*`, and ones
that cannot fire
- stop applying vitest rules to the playwright files in `tests/e2e`
- enable 7 stylelint rules, mostly `no-unknown` and `no-invalid` checks
- drop 2 unnecessary vendor prefixes (safari v17+, chrome v120+)
- look up ids via `querySelector` with `CSS.escape` instead of
`getElementById`
- remove stale doc about `@ts-expect-error`, it's forbidden
- misc dev doc fixes

Every declaration that `modern-normalize` v3 removes was checked against
chromium, webkit and firefox defaults first. The `hr` color and the
`:-moz-focusring` outline are kept as documented deviations, dropping
those does change rendering.

---------

Signed-off-by: silverwind <me@silverwind.io>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-08-20 09:57:56 -04:00

36 lines
1.7 KiB
TypeScript

import {navigateToIframeLink} from './render-iframe.ts';
import {captureNavigations} from '../utils/testhelper.ts';
describe('navigateToIframeLink', () => {
test('safe links', () => {
const navigations = captureNavigations();
const openSpy = vi.spyOn(window, 'open').mockImplementation(() => null);
navigateToIframeLink('http://example.com', '_blank');
expect(openSpy).toHaveBeenCalledWith('http://example.com/', '_blank', 'noopener,noreferrer');
navigateToIframeLink('https://example.com', '_self');
expect(navigations.at(-1)!.url).toEqual('https://example.com/');
navigateToIframeLink('https://example.com', null);
expect(navigations.at(-1)!.url).toEqual('https://example.com/');
navigateToIframeLink('/path', '');
expect(navigations.at(-1)!.url).toEqual(`${window.location.origin}/path`);
// input can be any type & any value, keep the same behavior as `window.location.href = 0`
navigateToIframeLink(0, {});
expect(navigations.at(-1)!.url).toEqual(`${window.location.origin}/0`);
expect(navigations).toHaveLength(4);
openSpy.mockRestore();
});
test('unsafe links', () => {
const navigations = captureNavigations();
const openSpy = vi.spyOn(window, 'open').mockImplementation(() => null);
const errorSpy = vi.spyOn(console, 'error').mockImplementation(() => undefined);
// eslint-disable-next-line no-script-url -- the test asserts that javascript: links are rejected
navigateToIframeLink('javascript:void(0);', '_blank');
navigateToIframeLink('data:image/svg+xml;utf8,<svg></svg>', '');
expect(openSpy).toHaveBeenCalledTimes(0);
expect(navigations).toEqual([]);
openSpy.mockRestore();
errorSpy.mockRestore();
});
});