home / client / test / bots.test.mjs
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
// The bots view, and with it the brains line — REMOTE PEER TEXT. Replays the
// recorded step script, including the unknown-key drop, the MAX_BRAINS cap,
// catalog ordering, and a value carrying markup (which must stay text).
import test from "node:test";
import assert from "node:assert/strict";
import { boot, flush, serialize, vectors } from "./harness.mjs";

const { env, lib } = await boot();
const v = vectors("bots");

test("bootBots replays every recorded step", async () => {
  const section = env.document.getElementById("bots");
  let states = {};
  let onlines = {};
  const api = {
    requestFriend: async () => true,
    stateOf: (pub) => states[pub] ?? null,
    onlineOf: (pub) => onlines[pub] ?? null,
  };

  lib.provideSocial(null);
  lib.bootBots(v.script.bots, v.script.apps);

  for (let i = 0; i < v.script.steps.length; i++) {
    const step = v.script.steps[i];
    states = step.states ?? {};
    onlines = step.onlines ?? {};
    lib.setLang(step.lang);
    lib.provideSocial(step.api ? api : null);
    await flush(40); // the id-kit fingerprints resolve off a platform task
    assert.equal(serialize(section), v.out[i].html, `step ${i}: ${step.label}`);
  }
  lib.setLang("en");
});

test("no innerHTML anywhere on the brains path", () => {
  // Structural, not incidental: assert the rendered nodes carry no raw markup
  // at all. The dom-stub only ever populates _html through innerHTML, so a
  // single innerHTML= on this path would show up as a non-null _html.
  const section = env.document.getElementById("bots");
  const walk = (n, out = []) => {
    if (n.nodeType === 1) {
      out.push(n);
      for (const c of n.childNodes) walk(c, out);
    }
    return out;
  };
  const els = walk(section);
  assert.ok(els.length > 5, "the section must actually be populated");
  for (const e of els) {
    assert.equal(e._html, null, `<${e.tagName}> was built with innerHTML`);
  }
});

test("a hostile brains value reaches the DOM as text, escaped", () => {
  const step = v.out.find((s) => s.label === "markup in a value stays text");
  assert.ok(step.html.includes("&lt;img src=x onerror=1&gt;"), "the value must be escaped text");
  assert.ok(!step.html.includes("<img"), "and never an element");
});

static mirror of HEAD · about · clone: git clone https://git.ardegazu.ro/home.git