#!/usr/bin/perl use warnings; use strict; use Test::More tests => 32; use Encode; BEGIN { use_ok("IkiWiki"); } # Initialize htmlscrubber plugin %config=IkiWiki::defaultconfig(); $config{srcdir}=$config{destdir}="/dev/null"; IkiWiki::loadplugins(); IkiWiki::checkconfig(); is(IkiWiki::htmlize("foo", "foo", "mdwn", "foo\n\nbar\n"), "

foo

\n\n

bar

\n", "basic"); is(IkiWiki::htmlize("foo", "foo", "mdwn", readfile("t/test1.mdwn")), Encode::decode_utf8(qq{

o\nóóóóó

\n}), "utf8; bug #373203"); ok(IkiWiki::htmlize("foo", "foo", "mdwn", readfile("t/test2.mdwn")), "this file crashes markdown if it's fed in as decoded utf-8"); sub gotcha { my $html=IkiWiki::htmlize("foo", "foo", "mdwn", shift); return $html =~ /GOTCHA/; } ok(!gotcha(q{click me}), "javascript url"); ok(!gotcha(q{click me}), "partially encoded javascript url"); ok(!gotcha(q{click me}), "jscript url"); ok(!gotcha(q{click me}), "vbscrpt url"); ok(!gotcha(q{click me}), "java-tab-script url"); ok(!gotcha(q{foo}), "entity-encoded CSS script test"); ok(!gotcha(q{foo}), "another entity-encoded CSS script test"); ok(!gotcha(q{}), "script tag"); ok(!gotcha(q{
foo
}), "form action with javascript"); ok(!gotcha(q{}), "video poster with javascript"); ok(!gotcha(q{a}), "CSS script test"); ok(! gotcha(q{}), "data:text/javascript (jeez!)"); ok(gotcha(q{}), "data:image/png"); ok(gotcha(q{}), "data:image/gif"); ok(gotcha(q{}), "data:image/jpeg"); ok(gotcha(q{

javascript:alert('GOTCHA')

}), "not javascript AFAIK (but perhaps some web browser would like to be perverse and assume it is?)"); ok(gotcha(q{}), "not javascript"); ok(gotcha(q{foo}), "not javascript"); is(IkiWiki::htmlize("foo", "foo", "mdwn", q{foo}), q{foo}, "img with alt tag allowed"); is(IkiWiki::htmlize("foo", "foo", "mdwn", q{}), q{}, "absolute url allowed"); is(IkiWiki::htmlize("foo", "foo", "mdwn", q{}), q{}, "relative url allowed"); is(IkiWiki::htmlize("foo", "foo", "mdwn", q{bar}), q{bar}, "class attribute allowed"); is(IkiWiki::htmlize("foo", "foo", "mdwn", q{}), q{}, "simple anchor allowed"); is(IkiWiki::htmlize("foo", "foo", "mdwn", q{}), q{}, "colon allowed in anchor"); is(IkiWiki::htmlize("foo", "foo", "mdwn", q{}), q{}, "colon allowed in query string"); is(IkiWiki::htmlize("foo", "foo", "mdwn", q{}), q{}, "unknown protocol blocked"); is(IkiWiki::htmlize("foo", "foo", "mdwn", q{}), q{}, "simple relative anchor allowed"); is(IkiWiki::htmlize("foo", "foo", "mdwn", q{}), q{}, "colon in simple relative anchor allowed");