require "test_helper"
class ActionText::Attachment::OpengraphEmbedTest < ActiveSupport::TestCase
test "keeps absolute http and https links and images" do
embed = embed_from href: "http://example.com/page", url: "https://example.com/image.png"
assert_equal "http://example.com/page", embed.href
assert_equal "https://example.com/image.png", embed.url
end
test "drops a link and an image that aren't web URLs" do
[ "javascript:alert(1)", "data:text/html,pwned", "vbscript:msgbox(1)", "//example.com/image.png",
"/rooms/1", "rooms/1", "", "http://exa mple.com/ ",
"https:/rooms/1", "https:rooms/1", "http:/rooms/1", "https://", "http://:80/rooms/1" ].each do |value|
embed = embed_from href: value, url: value
assert_nil embed.href, "expected #{value.inspect} to be dropped as a link"
assert_nil embed.url, "expected #{value.inspect} to be dropped as an image"
end
end
test "drops a link and an image on this Campfire's own host, however it is spelled" do
Current.set request: ActionDispatch::TestRequest.create("HTTP_HOST" => "once.campfire.test") do
[ "https://once.campfire.test/rooms/1", "http://once.campfire.test/rooms/1",
"https://ONCE.Campfire.Test/rooms/1", "https://once.campfire.test./rooms/1",
"https://%6fnce.campfire.test/rooms/1", "https://%77ww.example.com/x.png" ].each do |value|
embed = embed_from href: value, url: value
assert_nil embed.href, "expected #{value.inspect} to be dropped as a link"
assert_nil embed.url, "expected #{value.inspect} to be dropped as an image"
end
embed = embed_from href: "https://example.com/page", url: "https://example.com/image.png"
assert_equal "https://example.com/page", embed.href
assert_equal "https://example.com/image.png", embed.url
end
end
test "drops a link and an image on a bare address rather than a domain name" do
[ "http://127.0.0.1/rooms/1", "http://2130706433/rooms/1", "http://0177.0.0.1/rooms/1",
"http://0x7f.0.0.1/rooms/1", "http://1.2.3.0xff/rooms/1", "http://[::1]/rooms/1",
"http://localhost/rooms/1", "https://203.0.113.10/image.png" ].each do |value|
embed = embed_from href: value, url: value
assert_nil embed.href, "expected #{value.inspect} to be dropped as a link"
assert_nil embed.url, "expected #{value.inspect} to be dropped as an image"
end
end
test "keeps an internationalized domain written in punycode" do
embed = embed_from href: "https://xn--80aswg.xn--p1ai/page", url: "https://xn--80aswg.xn--p1ai/image.png"
assert_equal "https://xn--80aswg.xn--p1ai/page", embed.href
assert_equal "https://xn--80aswg.xn--p1ai/image.png", embed.url
end
test "renders the image and the link when both are web URLs" do
html = render_embed href: "https://example.com/page", url: "https://example.com/image.png"
assert_match %r{Title}, html
assert_match %r{
Title", caption: "
"
assert_no_match //, html
assert_no_match /
)
node = ActionText::Fragment.wrap(html).find_all(ActionText::Attachment.tag_name).first
ActionText::Attachment.from_node(node)
end
def embed_from(**attributes)
attachment_for(**attributes).attachable
end
def render_embed(**attributes)
attachment = attachment_for(**attributes)
ApplicationController.render partial: attachment.to_partial_path, locals: { opengraph_embed: attachment }
end
end