require "test_helper" class MessagesHelperTest < ActionView::TestCase test "message_presentation neutralizes unsafe URI schemes in links" do message = Message.create! room: rooms(:pets), body: '
x
', client_message_id: "0015", creator: users(:jason) presentation = view.message_presentation(message) assert_no_match /javascript:/, presentation assert_match /x<\/a>/, presentation end test "message_presentation strips event handler attributes from allowed tags" do message = Message.create! room: rooms(:pets), body: '
x
', client_message_id: "0015", creator: users(:jason) presentation = view.message_presentation(message) assert_no_match /onmouseover/, presentation assert_match /x<\/a>/, presentation end test "message_presentation preserves safe links and formatting" do message = Message.create! room: rooms(:pets), body: '
example bold
', client_message_id: "0015", creator: users(:jason) presentation = view.message_presentation(message) assert_match /]*>example<\/a>/, presentation assert_match /bold<\/strong>/, presentation end test "message_presentation shows an image's thumbnail made when it was posted" do presentation = view.message_presentation(attachment_message("moon.jpg", "image/jpeg", processed: true)) assert_match %r{]+src="[^"]*/representations/[^"]*moon\.jpg"}, presentation end test "message_presentation links an image whose thumbnail wasn't made, rather than making it on view" do presentation = view.message_presentation(attachment_message("moon.jpg", "image/jpeg", processed: false)) assert_no_match %r{/representations/}, presentation assert_match %r{moon\.jpg}, presentation end test "message_presentation gives a video the poster made when it was posted" do presentation = view.message_presentation(attachment_message("alpha-centuri.mov", "video/quicktime", processed: true)) assert_match %r{]+poster="[^"]*/representations/[^"]*alpha-centuri}, presentation end test "message_presentation shows a video whose poster wasn't made without one, rather than making it on view" do presentation = view.message_presentation(attachment_message("alpha-centuri.mov", "video/quicktime", processed: false)) assert_match %r{]+src="[^"]*alpha-centuri\.mov"}, presentation assert_no_match %r{poster=|/representations/}, presentation end test "message_presentation shows a video whose frame was drawn but whose poster wasn't made without one" do message = attachment_message("alpha-centuri.mov", "video/quicktime", processed: false) message.attachment.preview(format: :jpg).processed assert message.attachment.preview(:poster).processed? presentation = view.message_presentation(message.reload) assert_match %r{]+src="[^"]*alpha-centuri\.mov"}, presentation assert_no_match %r{poster=|/representations/}, presentation end private def attachment_message(file, content_type, processed:) attributes = { creator: users(:jason), client_message_id: "0015", attachment: fixture_file_upload(file, content_type) } if processed rooms(:pets).messages.create_with_attachment!(attributes) else rooms(:pets).messages.create!(attributes) end end end