2021-01-03 14:25:43 +05:30
|
|
|
import { sanitize } from '~/lib/dompurify';
|
|
|
|
|
|
|
|
// GDK
|
|
|
|
const rootGon = {
|
|
|
|
sprite_file_icons: '/assets/icons-123a.svg',
|
|
|
|
sprite_icons: '/assets/icons-456b.svg',
|
|
|
|
};
|
|
|
|
|
|
|
|
// Production
|
|
|
|
const absoluteGon = {
|
|
|
|
sprite_file_icons: `${window.location.protocol}//${window.location.hostname}/assets/icons-123a.svg`,
|
|
|
|
sprite_icons: `${window.location.protocol}//${window.location.hostname}/assets/icons-456b.svg`,
|
|
|
|
};
|
|
|
|
|
|
|
|
const expectedSanitized = '<svg><use></use></svg>';
|
|
|
|
|
|
|
|
const safeUrls = {
|
2021-03-08 18:12:59 +05:30
|
|
|
root: Object.values(rootGon).map((url) => `${url}#ellipsis_h`),
|
|
|
|
absolute: Object.values(absoluteGon).map((url) => `${url}#ellipsis_h`),
|
2021-01-03 14:25:43 +05:30
|
|
|
};
|
|
|
|
|
|
|
|
const unsafeUrls = [
|
|
|
|
'/an/evil/url',
|
|
|
|
'../../../evil/url',
|
2021-10-29 20:43:33 +05:30
|
|
|
'https://evil.url/assets/icons-123a.svg#test',
|
2021-01-03 14:25:43 +05:30
|
|
|
'https://evil.url/assets/icons-456b.svg',
|
|
|
|
`https://evil.url/${rootGon.sprite_icons}`,
|
|
|
|
`https://evil.url/${rootGon.sprite_file_icons}`,
|
|
|
|
`https://evil.url/${absoluteGon.sprite_icons}`,
|
|
|
|
`https://evil.url/${absoluteGon.sprite_file_icons}`,
|
2021-10-29 20:43:33 +05:30
|
|
|
`${rootGon.sprite_icons}/../evil/path`,
|
|
|
|
`${rootGon.sprite_file_icons}/../../evil/path`,
|
|
|
|
`${absoluteGon.sprite_icons}/../evil/path`,
|
|
|
|
`${absoluteGon.sprite_file_icons}/../../https://evil.url`,
|
2021-01-03 14:25:43 +05:30
|
|
|
];
|
|
|
|
|
2021-09-30 23:02:18 +05:30
|
|
|
const forbiddenDataAttrs = ['data-remote', 'data-url', 'data-type', 'data-method'];
|
|
|
|
const acceptedDataAttrs = ['data-random', 'data-custom'];
|
|
|
|
|
2021-01-03 14:25:43 +05:30
|
|
|
describe('~/lib/dompurify', () => {
|
|
|
|
let originalGon;
|
|
|
|
|
|
|
|
it('uses local configuration when given', () => {
|
|
|
|
// As dompurify uses a "Persistent Configuration", it might
|
|
|
|
// ignore config, this check verifies we respect
|
|
|
|
// https://github.com/cure53/DOMPurify#persistent-configuration
|
|
|
|
expect(sanitize('<br>', { ALLOWED_TAGS: [] })).toBe('');
|
|
|
|
expect(sanitize('<strong></strong>', { ALLOWED_TAGS: [] })).toBe('');
|
|
|
|
});
|
|
|
|
|
|
|
|
describe.each`
|
|
|
|
type | gon
|
|
|
|
${'root'} | ${rootGon}
|
|
|
|
${'absolute'} | ${absoluteGon}
|
|
|
|
`('when gon contains $type icon urls', ({ type, gon }) => {
|
|
|
|
beforeAll(() => {
|
|
|
|
originalGon = window.gon;
|
|
|
|
window.gon = gon;
|
|
|
|
});
|
|
|
|
|
|
|
|
afterAll(() => {
|
|
|
|
window.gon = originalGon;
|
|
|
|
});
|
|
|
|
|
|
|
|
it('allows no href attrs', () => {
|
|
|
|
const htmlHref = `<svg><use></use></svg>`;
|
|
|
|
expect(sanitize(htmlHref)).toBe(htmlHref);
|
|
|
|
});
|
|
|
|
|
2021-03-08 18:12:59 +05:30
|
|
|
it.each(safeUrls[type])('allows safe URL %s', (url) => {
|
2021-01-03 14:25:43 +05:30
|
|
|
const htmlHref = `<svg><use href="${url}"></use></svg>`;
|
|
|
|
expect(sanitize(htmlHref)).toBe(htmlHref);
|
|
|
|
|
|
|
|
const htmlXlink = `<svg><use xlink:href="${url}"></use></svg>`;
|
|
|
|
expect(sanitize(htmlXlink)).toBe(htmlXlink);
|
|
|
|
});
|
|
|
|
|
2021-03-08 18:12:59 +05:30
|
|
|
it.each(unsafeUrls)('sanitizes unsafe URL %s', (url) => {
|
2021-01-03 14:25:43 +05:30
|
|
|
const htmlHref = `<svg><use href="${url}"></use></svg>`;
|
|
|
|
const htmlXlink = `<svg><use xlink:href="${url}"></use></svg>`;
|
|
|
|
|
|
|
|
expect(sanitize(htmlHref)).toBe(expectedSanitized);
|
|
|
|
expect(sanitize(htmlXlink)).toBe(expectedSanitized);
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
describe('when gon does not contain icon urls', () => {
|
|
|
|
beforeAll(() => {
|
|
|
|
originalGon = window.gon;
|
|
|
|
window.gon = {};
|
|
|
|
});
|
|
|
|
|
|
|
|
afterAll(() => {
|
|
|
|
window.gon = originalGon;
|
|
|
|
});
|
|
|
|
|
2021-03-08 18:12:59 +05:30
|
|
|
it.each([...safeUrls.root, ...safeUrls.absolute, ...unsafeUrls])('sanitizes URL %s', (url) => {
|
2021-01-03 14:25:43 +05:30
|
|
|
const htmlHref = `<svg><use href="${url}"></use></svg>`;
|
|
|
|
const htmlXlink = `<svg><use xlink:href="${url}"></use></svg>`;
|
|
|
|
|
|
|
|
expect(sanitize(htmlHref)).toBe(expectedSanitized);
|
|
|
|
expect(sanitize(htmlXlink)).toBe(expectedSanitized);
|
|
|
|
});
|
|
|
|
});
|
2021-09-30 23:02:18 +05:30
|
|
|
|
|
|
|
describe('handles data attributes correctly', () => {
|
|
|
|
it.each(forbiddenDataAttrs)('removes %s attributes', (attr) => {
|
|
|
|
const htmlHref = `<a ${attr}="true">hello</a>`;
|
|
|
|
expect(sanitize(htmlHref)).toBe('<a>hello</a>');
|
|
|
|
});
|
|
|
|
|
|
|
|
it.each(acceptedDataAttrs)('does not remove %s attributes', (attr) => {
|
|
|
|
const attrWithValue = `${attr}="true"`;
|
|
|
|
const htmlHref = `<a ${attrWithValue}>hello</a>`;
|
|
|
|
expect(sanitize(htmlHref)).toBe(`<a ${attrWithValue}>hello</a>`);
|
|
|
|
});
|
|
|
|
});
|
2021-01-03 14:25:43 +05:30
|
|
|
});
|