Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7b99d421b8 |
@@ -1,9 +1,9 @@
|
||||
// The signature prompt shows a personal message as the bytes that are signed
|
||||
// (https://git.eeqj.de/sneak/AutistMask/issues/403): the raw data in hex, the
|
||||
// text it decodes to with control characters, line and paragraph separators
|
||||
// and characters that paint nothing marked rather than obeyed, laid out in
|
||||
// byte order, and a message that is not hex as plain text that cannot be
|
||||
// signed.
|
||||
// and characters that paint nothing marked rather than obeyed, markup shown as
|
||||
// text, laid out in byte order, and a message that is not hex as plain text
|
||||
// that cannot be signed.
|
||||
//
|
||||
// Driven against a minimal DOM stub in the shape
|
||||
// tests/approvalOrigin.test.js uses. That the layout keeps right-to-left
|
||||
@@ -178,6 +178,20 @@ test("a line feed is shown as a line break", async () => {
|
||||
expect(node("approve-sign-message").innerHTML).toBe("Sign in<br>Nonce: 7");
|
||||
});
|
||||
|
||||
// The message box is written as HTML, so a site's markup has to arrive there
|
||||
// escaped, as the text it is.
|
||||
const MARKUP = "<b>x</b><img src=x onerror=alert(1)>";
|
||||
|
||||
test.each([
|
||||
["a hex message", hexlify(toUtf8Bytes(MARKUP))],
|
||||
["a message that is not hex", MARKUP],
|
||||
])("markup in %s is shown as text, not as markup", async (_, message) => {
|
||||
await openPersonalSign(message);
|
||||
expect(node("approve-sign-message").innerHTML).toBe(
|
||||
"<b>x</b><img src=x onerror=alert(1)>",
|
||||
);
|
||||
});
|
||||
|
||||
test("the raw hex is shown alongside the text", async () => {
|
||||
await openPersonalSign("0x48656c6c6f");
|
||||
expect(shownMessage()).toBe("Hello");
|
||||
|
||||
Reference in New Issue
Block a user