Skip to content

test: cover safeUrl and sanitizeUrl script-scheme guards - #345

Open
readyagentsdev wants to merge 1 commit into
nirholas:mainfrom
readyagentsdev:test/342-url-scheme-guards
Open

readyagentsdev wants to merge 1 commit into
nirholas:mainfrom
readyagentsdev:test/342-url-scheme-guards

Conversation

@readyagentsdev

@readyagentsdev readyagentsdev commented Sep 30, 2026 •

Copy link
Copy Markdown

Closes #342.

Adds tests/url-scheme-guards.test.js: table-driven tests for safeUrl (src/safe-url.js) and sanitizeUrl (src/shared/sanitize-url.js). Tests only, no source changes.

Covered

  • javascript:, data:, vbscript: in mixed casing and with leading whitespace fall back (default '#' and a custom fallback for safeUrl)
  • protocol-relative //host is rejected
  • allowed shapes pass through: http(s)://, root-relative /path, #anchor
  • non-strings and blank input
  • a small block pinning the current intentional differences between the two (mailto:, ./ / ../, trimming, and https:example.com without slashes, which only safeUrl accepts)

Not pinned, worth a look: both functions currently accept /\evil.com. Browsers normalise a leading /\ to //, so as an href this navigates to evil.com. I left it out of the tests rather than locking in either behaviour, so you can decide whether it should be rejected.

npx vitest run tests/url-scheme-guards.test.js: 102 passed. prettier --check clean.

Signed-off-by: Agent G <326687097+readyagentsdev@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Tests: cover the safeUrl and sanitizeUrl script-scheme guards

1 participant