daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

highlight.test.mjs (1309B)


      1 import { test } from 'node:test';
      2 import assert from 'node:assert/strict';
      3 import { loadTs } from './_loadts.mjs';
      4 
      5 const { escapeHtml, highlightCommand } = await loadTs('src/lib/highlight.ts');
      6 
      7 test('escapeHtml neutralises markup and attribute delimiters', () => {
      8   const out = escapeHtml('<b onclick="x">&</b>');
      9   assert.ok(!out.includes('<'));
     10   assert.ok(!out.includes('>'));
     11   assert.ok(!out.includes('"'));
     12   assert.equal(out, '&lt;b onclick=&quot;x&quot;&gt;&amp;&lt;/b&gt;');
     13   assert.equal(escapeHtml(123), '123');
     14 });
     15 
     16 test('highlightCommand never emits raw input markup', () => {
     17   const out = highlightCommand('echo <script>alert(1)</script> "a<b"');
     18   assert.ok(!/<script/.test(out));
     19   assert.ok(!out.includes('a<b'));
     20   assert.ok(out.includes('&lt;script&gt;'));
     21 });
     22 
     23 test('highlightCommand token classes', () => {
     24   const out = highlightCommand('sudo tar -cf /dev/null 10.10.10.10 | sh');
     25   assert.match(out, /<span class="tk-cmd">sudo<\/span>/);
     26   assert.match(out, /<span class="tk-flag">-cf<\/span>/);
     27   assert.match(out, /<span class="tk-num">10\.10\.10\.10<\/span>/);
     28   assert.match(out, /<span class="tk-op">\|<\/span>/);
     29   assert.equal(highlightCommand('# a comment'), '<span class="tk-muted"># a comment</span>');
     30   assert.equal(highlightCommand('a\nb').split('\n').length, 2);
     31 });