aboutsummaryrefslogtreecommitdiff
path: root/internal/web/render_test.go
diff options
context:
space:
mode:
authorLukasz Kasprzak <lukas@labunix.xyz>2026-07-28 12:50:31 +0200
committerLukasz Kasprzak <lukas@labunix.xyz>2026-07-28 12:50:31 +0200
commit7b220084cf3951c8cde0582efdfcf628afc64336 (patch)
treee74bae03c61b62479ef4f68b046e3345618933c8 /internal/web/render_test.go
parentfeede51697be870ae183a95b513ef64f031dbd0f (diff)
downloadlectio-7b220084cf3951c8cde0582efdfcf628afc64336.tar.gz
lectio-7b220084cf3951c8cde0582efdfcf628afc64336.zip
refactor: remove the niedziela/missalemeum scrapers, bt, traditional_lang
The daily view now computes entirely offline (previous commit), so retire the network path and everything that served it: - Delete internal/tradlit (missalemeum) and the niedziela scraper from internal/liturgy (fetch/store/parse + fixtures); keep Section, DayInfo and ExtractCitation. - Remove the "bt" version everywhere (render gatherBT + branches, config, i18n, web form, TUI) and bible.ToEnglishRef (Polish citation converter). A legacy config carrying "bt" migrates to "wuj" on load (config.migrateBT). - Remove the traditional_lang config field and the -g/--lang flag from all three binaries. - Drop the now-dead flags -R/--refresh, -o/--offline, -u/--update, -C/--clean and the harvest/clean commands. - New defaults: versions = wuj,vul,grb,drb; default_version = vul. Update the README (offline-by-design, no harvest/update), help text, and stale niedziela/bt doc comments. Tests updated for the offline reality; go test ./... and go vet ./... are clean, all three binaries build and run offline (OF + EF, compare, web).
Diffstat (limited to 'internal/web/render_test.go')
-rw-r--r--internal/web/render_test.go16
1 files changed, 11 insertions, 5 deletions
diff --git a/internal/web/render_test.go b/internal/web/render_test.go
index c05a83c..39bcc58 100644
--- a/internal/web/render_test.go
+++ b/internal/web/render_test.go
@@ -80,13 +80,19 @@ func TestThemeCSSGuardRejectsInvalidNames(t *testing.T) {
}
func TestRenderReadingsEscapesScriptText(t *testing.T) {
+ // An attacker-controlled version code (?v=... reaches RenderReadings
+ // unfiltered) flows to render.GatherVersion as both the column label and the
+ // "(not in %s)" note. RenderReadings must HTML-escape it: it renders through
+ // html/template, never wrapping untrusted text in template.HTML.
+ const evil = "<script>alert(1)</script>"
secs := []liturgy.Section{{
- Heading: "Test",
- PartID: "pierwsze_czytanie",
- Paragraphs: [][]string{{"<script>alert(1)</script>"}},
+ Heading: "Ewangelia",
+ Citation: "J 20, 1. 11-18",
+ Ref: "John 20:1,11-18",
+ PartID: "pierwsze_czytanie",
}}
- html := string(RenderReadings(secs, []string{"bt"}, "new", "horizontal", "pl", liturgy.DayInfo{}))
- if strings.Contains(html, "<script>alert(1)</script>") {
+ html := string(RenderReadings(secs, []string{evil}, "new", "horizontal", "pl", liturgy.DayInfo{}))
+ if strings.Contains(html, evil) {
t.Errorf("raw <script> leaked into rendered output: %q", html)
}
if !strings.Contains(html, "&lt;script&gt;alert(1)&lt;/script&gt;") {