flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/apps/web/app/lib/next.test.ts

41 lines1,409 bytesCodeBlame
1import assert from "node:assert/strict";
2import { test } from "node:test";
3
4import { safeNext, withNext } from "./next.ts";
5
6test("a path on g1t is kept, with its query and fragment", () => {
7 assert.equal(safeNext("/acme/web"), "/acme/web");
8 assert.equal(safeNext("/acme/web/issues?state=closed#top"), "/acme/web/issues?state=closed#top");
9 assert.equal(safeNext("/device?code=ABCD-EFGH"), "/device?code=ABCD-EFGH");
10});
11
12test("anything that could leave g1t goes home instead", () => {
13 for (const raw of [
14 null,
15 undefined,
16 "",
17 "acme/web",
18 "https://evil.example/",
19 "//evil.example/",
20 "/\\evil.example/",
21 "/\\/evil.example/",
22 "\\\\evil.example",
23 "/%5C%5Cevil.example".replace(/%5C/g, "\\"),
24 "/\t/evil.example",
25 "/\n/evil.example",
26 "/%0a",
27 "javascript:alert(1)",
28 ]) {
29 const kept = safeNext(raw);
30 // An encoded newline is still a path on g1t.
31 if (raw === "/%0a") assert.equal(kept, "/%0a");
32 else assert.equal(kept, "/", String(raw));
33 }
34});
35
36test("sign in and sign up links carry where to come back to", () => {
37 assert.equal(withNext("/login", "/acme/web/issues?state=open"), "/login?next=%2Facme%2Fweb%2Fissues%3Fstate%3Dopen");
38 assert.equal(withNext("/register", "/explore"), "/register?next=%2Fexplore");
39 assert.equal(withNext("/login", "/"), "/login");
40 assert.equal(withNext("/login", "//evil.example"), "/login");
41});