aboutsummaryrefslogtreecommitdiff
path: root/internal/web/render_test.go
diff options
context:
space:
mode:
Diffstat (limited to 'internal/web/render_test.go')
-rw-r--r--internal/web/render_test.go20
1 files changed, 13 insertions, 7 deletions
diff --git a/internal/web/render_test.go b/internal/web/render_test.go
index 6002927..39bcc58 100644
--- a/internal/web/render_test.go
+++ b/internal/web/render_test.go
@@ -80,13 +80,19 @@ func TestThemeCSSGuardRejectsInvalidNames(t *testing.T) {
}
func TestRenderReadingsEscapesScriptText(t *testing.T) {
+ // An attacker-controlled version code (?v=... reaches RenderReadings
+ // unfiltered) flows to render.GatherVersion as both the column label and the
+ // "(not in %s)" note. RenderReadings must HTML-escape it: it renders through
+ // html/template, never wrapping untrusted text in template.HTML.
+ const evil = "<script>alert(1)</script>"
secs := []liturgy.Section{{
- Heading: "Test",
- PartID: "pierwsze_czytanie",
- Paragraphs: [][]string{{"<script>alert(1)</script>"}},
+ Heading: "Ewangelia",
+ Citation: "J 20, 1. 11-18",
+ Ref: "John 20:1,11-18",
+ PartID: "pierwsze_czytanie",
}}
- html := string(RenderReadings(secs, []string{"bt"}, "new", "horizontal", "pl", liturgy.DayInfo{}))
- if strings.Contains(html, "<script>alert(1)</script>") {
+ html := string(RenderReadings(secs, []string{evil}, "new", "horizontal", "pl", liturgy.DayInfo{}))
+ if strings.Contains(html, evil) {
t.Errorf("raw <script> leaked into rendered output: %q", html)
}
if !strings.Contains(html, "&lt;script&gt;alert(1)&lt;/script&gt;") {
@@ -109,7 +115,7 @@ func TestRenderReadingsVertical(t *testing.T) {
}
func TestRenderReadingsInterlinear(t *testing.T) {
- secs := []liturgy.Section{{Heading: "Ewangelia (J 20, 1. 11-18)", PartID: "ewangelia"}}
+ secs := []liturgy.Section{{Heading: "Ewangelia", Citation: "J 20, 1. 11-18", Ref: "John 20:1,11-18", PartID: "ewangelia"}}
html := string(RenderReadings(secs, []string{"wuj", "vul"}, "new", "interlinear", "pl", liturgy.DayInfo{}))
if !strings.Contains(html, "ilverse") {
t.Errorf("interlinear output missing ilverse: %q", html[:min(300, len(html))])
@@ -130,7 +136,7 @@ func TestRenderReadingsInterlinear(t *testing.T) {
}
func TestRenderReadingsInterlinearExcludesBT(t *testing.T) {
- secs := []liturgy.Section{{Heading: "Ewangelia (J 20, 1. 11-18)", PartID: "ewangelia"}}
+ secs := []liturgy.Section{{Heading: "Ewangelia", Citation: "J 20, 1. 11-18", Ref: "John 20:1,11-18", PartID: "ewangelia"}}
html := string(RenderReadings(secs, []string{"bt", "vul"}, "new", "interlinear", "pl", liturgy.DayInfo{}))
if strings.Contains(html, "Biblia TysiÄ…clecia (niedziela.pl)") {
t.Errorf("interlinear output should substitute wuj for bt, not carry bt's label: %q", html[:min(300, len(html))])