// The bots view, and with it the brains line — REMOTE PEER TEXT. Replays the
// recorded step script, including the unknown-key drop, the MAX_BRAINS cap,
// catalog ordering, and a value carrying markup (which must stay text).
import test from "node:test";
import assert from "node:assert/strict";
import { boot, flush, serialize, vectors } from "./harness.mjs";
const { env, lib } = await boot();
const v = vectors("bots");
test("bootBots replays every recorded step", async () => {
const section = env.document.getElementById("bots");
let states = {};
let onlines = {};
const api = {
requestFriend: async () => true,
stateOf: (pub) => states[pub] ?? null,
onlineOf: (pub) => onlines[pub] ?? null,
};
lib.provideSocial(null);
lib.bootBots(v.script.bots, v.script.apps);
for (let i = 0; i < v.script.steps.length; i++) {
const step = v.script.steps[i];
states = step.states ?? {};
onlines = step.onlines ?? {};
lib.setLang(step.lang);
lib.provideSocial(step.api ? api : null);
await flush(40); // the id-kit fingerprints resolve off a platform task
assert.equal(serialize(section), v.out[i].html, `step ${i}: ${step.label}`);
}
lib.setLang("en");
});
test("no innerHTML anywhere on the brains path", () => {
// Structural, not incidental: assert the rendered nodes carry no raw markup
// at all. The dom-stub only ever populates _html through innerHTML, so a
// single innerHTML= on this path would show up as a non-null _html.
const section = env.document.getElementById("bots");
const walk = (n, out = []) => {
if (n.nodeType === 1) {
out.push(n);
for (const c of n.childNodes) walk(c, out);
}
return out;
};
const els = walk(section);
assert.ok(els.length > 5, "the section must actually be populated");
for (const e of els) {
assert.equal(e._html, null, `<${e.tagName}> was built with innerHTML`);
}
});
test("a hostile brains value reaches the DOM as text, escaped", () => {
const step = v.out.find((s) => s.label === "markup in a value stays text");
assert.ok(step.html.includes("<img src=x onerror=1>"), "the value must be escaped text");
assert.ok(!step.html.includes("<img"), "and never an element");
});