Target names, URLs and log lines reach the page as text (closes #29)
check / check (push) Successful in 3m8s
check / check (push) Successful in 3m8s
A host row escapes the name and URL it writes into its markup with a new escapeHTML function, and the debug log builds each line as an element whose text is set, so neither is read as HTML once targets can be configured. A unit test builds the row of a target whose name and URL hold < > " & and ' and checks each comes out escaped; hostRowHTML is exported for it. README.md stops calling CONFIG frozen: the interval menu sets updateInterval, and the timeouts, history span and axis ticks are computed from it. AppState declares _recoveryProbeId and _recoveryProbeChecks, the sparkline axis functions drop the parameters they never used, and HostState's history comment names both entry shapes. Model: opus-5-5
This commit was merged in pull request #105.
This commit is contained in:
@@ -8,6 +8,7 @@ import {
|
||||
AppState,
|
||||
CONFIG,
|
||||
greyOutUI,
|
||||
hostRowHTML,
|
||||
HostState,
|
||||
humanDuration,
|
||||
latencyClass,
|
||||
@@ -230,6 +231,32 @@ test("at a 30000ms interval, after the user pauses and resumes during a round, n
|
||||
}
|
||||
});
|
||||
|
||||
// The page shows < > " & and ' in a row's markup as
|
||||
// < > " & and '.
|
||||
test(`a target whose name and URL hold < > " & and ' shows those characters in its row`, () => {
|
||||
const host = new HostState({
|
||||
name: `<b>"x" & 'y'</b>`,
|
||||
url: `https://x.test/<b>?a="x"&b='y'`,
|
||||
});
|
||||
const row = hostRowHTML(host, 0);
|
||||
assert.doesNotMatch(row, /<b>/);
|
||||
assert.ok(
|
||||
row.includes(
|
||||
"><b>"x" & 'y'</b></span>",
|
||||
),
|
||||
);
|
||||
assert.ok(
|
||||
row.includes(
|
||||
'href="https://x.test/<b>?a="x"&b='y'"',
|
||||
),
|
||||
);
|
||||
assert.ok(
|
||||
row.includes(
|
||||
">https://x.test/<b>?a="x"&b='y'</a>",
|
||||
),
|
||||
);
|
||||
});
|
||||
|
||||
for (const [seconds, text] of [
|
||||
[0, "0s"],
|
||||
[1, "1s"],
|
||||
|
||||
Reference in New Issue
Block a user