9c9c34fccf
Migrates `twenty-front`, `twenty-sdk`, and `twenty-front-component-renderer` from `twenty-ui-deprecated` to `twenty-ui` (mechanical import swap — the packages have API parity) and deletes the deprecated package along with its workspace/CI/config wiring. Also adds `@linaria/react`/`@linaria/core` as direct deps of `twenty-front` (it used them transitively via the deprecated package). Note: move the required status check from `ci-ui-status-check` to `ci-new-ui-status-check`. Argos: the Storybook box-model/button-reset baseline shift (the bulk of the visual diffs) is isolated in #21665 — Storybook now loads twenty-ui's global `reset.scss`, which the production app already ships. Once #21665 merges and this branch is rebased, the remaining Argos diffs are component-level visual-parity items only.
37 lines
1.2 KiB
TypeScript
37 lines
1.2 KiB
TypeScript
import { getSafeUrl } from '../getSafeUrl';
|
|
|
|
describe('getSafeUrl', () => {
|
|
it('returns safe absolute urls unchanged', () => {
|
|
expect(getSafeUrl('https://twenty.com')).toBe('https://twenty.com');
|
|
expect(getSafeUrl('http://twenty.com')).toBe('http://twenty.com');
|
|
expect(getSafeUrl('mailto:hello@twenty.com')).toBe(
|
|
'mailto:hello@twenty.com',
|
|
);
|
|
expect(getSafeUrl('tel:+33123456789')).toBe('tel:+33123456789');
|
|
});
|
|
|
|
it('keeps relative paths', () => {
|
|
expect(getSafeUrl('/settings/profile')).toBe('/settings/profile');
|
|
});
|
|
|
|
it('prepends https to scheme-less urls', () => {
|
|
expect(getSafeUrl('twenty.com')).toBe('https://twenty.com');
|
|
});
|
|
|
|
it('rejects dangerous schemes', () => {
|
|
expect(getSafeUrl('javascript:alert(1)')).toBeUndefined();
|
|
expect(getSafeUrl('JavaScript:alert(1)')).toBeUndefined();
|
|
expect(
|
|
getSafeUrl('data:text/html,<script>alert(1)</script>'),
|
|
).toBeUndefined();
|
|
expect(getSafeUrl('vbscript:msgbox(1)')).toBeUndefined();
|
|
});
|
|
|
|
it('returns undefined for empty or nullish values', () => {
|
|
expect(getSafeUrl('')).toBeUndefined();
|
|
expect(getSafeUrl(' ')).toBeUndefined();
|
|
expect(getSafeUrl(undefined)).toBeUndefined();
|
|
expect(getSafeUrl(null)).toBeUndefined();
|
|
});
|
|
});
|