package web import ( "os/exec" "strings" "testing" ) func TestCommandPreviewQuotesAndEscapesArbitraryArguments(t *testing.T) { parts := []string{"luci", "repo", `name; $(touch nope) ' " `} if got, want := commandText(parts...), `luci repo r#'name; $(touch nope) ' " '#`; got != want { t.Fatalf("command=%q want=%q", got, want) } html := string(highlightCommand(parts...)) if strings.Contains(html, "") || !strings.Contains(html, "<tag>") || !strings.Contains(html, "command-name") { t.Fatalf("unsafe preview=%s", html) } } func TestNuQuotePreservesArbitraryExternalArguments(t *testing.T) { if _, err := exec.LookPath("nu"); err != nil { t.Skip("Nushell not installed") } values := []string{"apostrophe's", `"$env.HOME $(nope)`, "line one\nline two", "--repo", "r#'closes'#"} quoted := make([]string, len(values)) for i, value := range values { quoted[i] = nuQuote(value) } command := "^printf '<%s>\\n' " + strings.Join(quoted, " ") output, err := exec.Command("nu", "--no-config-file", "-c", command).CombinedOutput() if err != nil { t.Fatalf("nu failed: %v\ncommand=%s\noutput=%s", err, command, output) } want := "<" + strings.Join(values, ">\n<") + ">\n" if string(output) != want { t.Fatalf("arguments=%q want=%q", output, want) } } func TestHighlightKDLEscapesSourceAndKeepsSyntax(t *testing.T) { html := string(HighlightKDL("job \"\" // note\nrun \"echo ok\"")) for _, want := range []string{`class="kdl-keyword">job`, `class="kdl-string">"</span><script>alert(1)</script>"`, `class="kdl-comment">// note`} { if !strings.Contains(html, want) { t.Fatalf("missing %q in %s", want, html) } } if strings.Contains(html, "