require "test_helper" class MessagesHelperTest < ActionView::TestCase test "message_presentation neutralizes unsafe URI schemes in links" do message = Message.create! room: rooms(:pets), body: '
', client_message_id: "0015", creator: users(:jason) presentation = view.message_presentation(message) assert_no_match /javascript:/, presentation assert_match /x<\/a>/, presentation end test "message_presentation strips event handler attributes from allowed tags" do message = Message.create! room: rooms(:pets), body: '', client_message_id: "0015", creator: users(:jason) presentation = view.message_presentation(message) assert_no_match /onmouseover/, presentation assert_match /x<\/a>/, presentation end test "message_presentation preserves safe links and formatting" do message = Message.create! room: rooms(:pets), body: '