daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

hero-and-shelves.test.mjs (2547B)


      1 import assert from 'node:assert/strict';
      2 import { readFile } from 'node:fs/promises';
      3 import test from 'node:test';
      4 import { Window } from 'happy-dom';
      5 
      6 async function documentAt(route) {
      7   const window = new Window();
      8   window.document.write(await readFile(new URL(`../dist/${route}index.html`, import.meta.url), 'utf8'));
      9   return window.document;
     10 }
     11 
     12 test('dot fields belong to page heroes and never the reading area', async () => {
     13   for (const route of ['', 'osint/']) {
     14     const document = await documentAt(route);
     15     const fields = [...document.querySelectorAll('[data-signal]')];
     16     assert.equal(fields.length, 1, route);
     17     assert.ok(fields[0].parentElement.classList.contains('signal-hero'), route);
     18     assert.equal(document.querySelector('body > [data-signal], article [data-signal]'), null, route);
     19     assert.equal(fields[0].hasAttribute('data-astro-transition-persist'), false, route);
     20   }
     21 });
     22 
     23 test('sheet headers carry the fuzz field, not the dot field', async () => {
     24   const document = await documentAt('sheets/enumeration/2-4-cheatsheet-gitleaks/');
     25   assert.equal(document.querySelectorAll('[data-signal]').length, 0);
     26   const fuzz = [...document.querySelectorAll('[data-fuzz]')];
     27   assert.equal(fuzz.length, 1);
     28   assert.ok(fuzz[0].closest('.signal-hero'));
     29   assert.equal(document.querySelector('article [data-fuzz]'), null);
     30 });
     31 
     32 test('home has one h1 and a skip link to main', async () => {
     33   const document = await documentAt('');
     34   assert.equal(document.querySelectorAll('h1').length, 1);
     35   assert.equal(document.querySelector('a.skip-link')?.getAttribute('href'), '#main');
     36   assert.ok(document.querySelector('main#main'));
     37 });
     38 
     39 test('OSINT and Enumeration both link to the original secret-scanner sheets', async () => {
     40   for (const route of ['osint/', 'enumeration/']) {
     41     const document = await documentAt(route);
     42     for (const slug of ['2-4-cheatsheet-gitleaks', '2-5-cheatsheet-trufflehog']) {
     43       assert.equal(document.querySelectorAll(`a.rec[href="/sheets/enumeration/${slug}"]`).length, 1, `${route}: ${slug}`);
     44     }
     45   }
     46 });
     47 
     48 test('secret-scanner instructions render as prose after the installation block', async () => {
     49   for (const slug of ['2-4-cheatsheet-gitleaks', '2-5-cheatsheet-trufflehog']) {
     50     const document = await documentAt(`sheets/enumeration/${slug}/`);
     51     const headings = [...document.querySelectorAll('article h2')].map((h) => h.textContent);
     52     assert.ok(headings.includes('Subcommands at a Glance'), slug);
     53     assert.ok(document.querySelector('article table'), slug);
     54   }
     55 });