- Restrict assistant-rendered images to the active deployment origin\n- Cover local and self-hosted origins without hardcoded production hosts\n- Verify cross-origin, insecure, and data image rejection in browser tests\n\nCo-authored-by: Jason Kneen <jason.kneen@bouncingfish.com>
27 lines
1.1 KiB
TypeScript
27 lines
1.1 KiB
TypeScript
import { describe, expect, test } from 'bun:test'
|
|
|
|
import { createMarkdownHardenOptions } from '@/app/shell/markdown/config'
|
|
import { markdownRenderKey } from '@/app/shell/markdown/state'
|
|
|
|
describe('chat Markdown rendering state', () => {
|
|
test('keeps one parser while streaming and remounts when content settles', () => {
|
|
expect(markdownRenderKey({ mode: 'streaming', surface: 'message' })).toBe('message-streaming')
|
|
expect(markdownRenderKey({ mode: 'static', surface: 'message' })).toBe('message-static')
|
|
})
|
|
|
|
test('derives the image allowlist from the runtime origin', () => {
|
|
expect(createMarkdownHardenOptions('http://localhost:1420')).toMatchObject({
|
|
allowedImagePrefixes: ['http://localhost:1420/']
|
|
})
|
|
expect(createMarkdownHardenOptions('https://design.example.org/app')).toMatchObject({
|
|
allowedImagePrefixes: ['https://design.example.org/']
|
|
})
|
|
})
|
|
|
|
test('isolates reasoning parser keys from response parser keys', () => {
|
|
expect(markdownRenderKey({ mode: 'streaming', surface: 'reasoning' })).toBe(
|
|
'reasoning-streaming'
|
|
)
|
|
})
|
|
})
|