35 lines
1008 B
Python
35 lines
1008 B
Python
# retoor <retoor@molodetz.nl>
|
|||
|
|
from molodetz.rendering import content_preview, normalize_dashes, plain_title, render_content, render_title
|
||
|
|
|
||
|
|
|
||
|
|
def test_markdown_renders_and_escapes_html():
|
||
|
|
html = render_content("**vet** <script>alert(1)</script>")
|
||
|
|
assert "<strong>vet</strong>" in html
|
||
|
|
assert "<script>" not in html
|
||
|
|
|
||
|
|
|
||
|
|
def test_dashes_are_normalized():
|
||
|
|
long_dash = chr(0x2014)
|
||
|
|
assert normalize_dashes(f"a {long_dash} b") == "a - b"
|
||
|
|
assert long_dash not in render_content(f"x {long_dash} y")
|
||
|
|
|
||
|
|
|
||
|
|
def test_javascript_urls_are_dropped():
|
||
|
|
html = render_content("[klik](javascript:alert(1))")
|
||
|
|
assert "javascript:" not in html
|
||
|
|
|
||
|
|
|
||
|
|
def test_emoji_shortcodes():
|
||
|
|
assert "\U0001F44D" in render_content(":thumbsup:")
|
||
|
|
|
||
|
|
|
||
|
|
def test_title_is_inline_only():
|
||
|
|
html = render_title("# Kop *nadruk*")
|
||
|
|
assert "<h1>" not in html
|
||
|
|
assert plain_title("**Vet** titel") == "Vet titel"
|
||
|
|
|
||
|
|
|
||
|
|
def test_preview_truncates():
|
||
|
|
preview = content_preview("woord " * 200, 50)
|
||
|
|
assert len(preview) <= 52
|