Files
twenty/packages/twenty-ui/src/utilities/utils/__tests__/getSafeUrl.test.ts
T
Raphaël Bosi 9c9c34fccf Remove twenty-ui-deprecated and migrate frontend to twenty-ui (#21596)
Migrates `twenty-front`, `twenty-sdk`, and
`twenty-front-component-renderer` from `twenty-ui-deprecated` to
`twenty-ui` (mechanical import swap — the packages have API parity) and
deletes the deprecated package along with its workspace/CI/config
wiring.

Also adds `@linaria/react`/`@linaria/core` as direct deps of
`twenty-front` (it used them transitively via the deprecated package).

Note: move the required status check from `ci-ui-status-check` to
`ci-new-ui-status-check`.

Argos: the Storybook box-model/button-reset baseline shift (the bulk of
the visual diffs) is isolated in #21665 — Storybook now loads
twenty-ui's global `reset.scss`, which the production app already ships.
Once #21665 merges and this branch is rebased, the remaining Argos diffs
are component-level visual-parity items only.
2026-06-17 09:41:11 +00:00

37 lines
1.2 KiB
TypeScript

import { getSafeUrl } from '../getSafeUrl';
describe('getSafeUrl', () => {
it('returns safe absolute urls unchanged', () => {
expect(getSafeUrl('https://twenty.com')).toBe('https://twenty.com');
expect(getSafeUrl('http://twenty.com')).toBe('http://twenty.com');
expect(getSafeUrl('mailto:hello@twenty.com')).toBe(
'mailto:hello@twenty.com',
);
expect(getSafeUrl('tel:+33123456789')).toBe('tel:+33123456789');
});
it('keeps relative paths', () => {
expect(getSafeUrl('/settings/profile')).toBe('/settings/profile');
});
it('prepends https to scheme-less urls', () => {
expect(getSafeUrl('twenty.com')).toBe('https://twenty.com');
});
it('rejects dangerous schemes', () => {
expect(getSafeUrl('javascript:alert(1)')).toBeUndefined();
expect(getSafeUrl('JavaScript:alert(1)')).toBeUndefined();
expect(
getSafeUrl('data:text/html,<script>alert(1)</script>'),
).toBeUndefined();
expect(getSafeUrl('vbscript:msgbox(1)')).toBeUndefined();
});
it('returns undefined for empty or nullish values', () => {
expect(getSafeUrl('')).toBeUndefined();
expect(getSafeUrl(' ')).toBeUndefined();
expect(getSafeUrl(undefined)).toBeUndefined();
expect(getSafeUrl(null)).toBeUndefined();
});
});