#!/usr/bin/perl use warnings; use strict; use Test::More tests => 32; use Encode; BEGIN { use_ok("IkiWiki"); } # Initialize htmlscrubber plugin %config=IkiWiki::defaultconfig(); $config{srcdir}=$config{destdir}="/dev/null"; IkiWiki::loadplugins(); IkiWiki::checkconfig(); is(IkiWiki::htmlize("foo", "foo", "mdwn", "foo\n\nbar\n"), "
foo
\n\nbar
\n", "basic"); is(IkiWiki::htmlize("foo", "foo", "mdwn", readfile("t/test1.mdwn")), Encode::decode_utf8(qq{
\nóóóóó
javascript:alert('GOTCHA')
}), "not javascript AFAIK (but perhaps some web browser would like to be perverse and assume it is?)"); ok(gotcha(q{
}), "not javascript");
ok(gotcha(q{foo}), "not javascript");
is(IkiWiki::htmlize("foo", "foo", "mdwn",
q{
}),
q{
}, "img with alt tag allowed");
is(IkiWiki::htmlize("foo", "foo", "mdwn",
q{}),
q{}, "absolute url allowed");
is(IkiWiki::htmlize("foo", "foo", "mdwn",
q{}),
q{}, "relative url allowed");
is(IkiWiki::htmlize("foo", "foo", "mdwn",
q{bar}),
q{bar}, "class attribute allowed");
is(IkiWiki::htmlize("foo", "foo", "mdwn",
q{}),
q{}, "simple anchor allowed");
is(IkiWiki::htmlize("foo", "foo", "mdwn",
q{}),
q{}, "colon allowed in anchor");
is(IkiWiki::htmlize("foo", "foo", "mdwn",
q{}),
q{}, "colon allowed in query string");
is(IkiWiki::htmlize("foo", "foo", "mdwn",
q{}),
q{}, "unknown protocol blocked");
is(IkiWiki::htmlize("foo", "foo", "mdwn",
q{}),
q{}, "simple relative anchor allowed");
is(IkiWiki::htmlize("foo", "foo", "mdwn",
q{}),
q{}, "colon in simple relative anchor allowed");