Files
simplex-chat/apps/simplex-badge-service/web/test/embed.test.ts
T
19e70faeec badges: webapp feature branch (#7548)
* badges: webapp (#7433)

* badges: service migrations, store and catalog

* badges: BTCPay provider and settlement poller

* badges: web listener and /api endpoints

* web: checkout single-page app

* badges: tests and BTCPay fixtures

* badges: README and ini reference

* badges: fix hex16 build on GHC 8.10.7

* badges: Stripe card lane

* badges: fix Stripe card checkout, add theming

* badges: add a discount row to the order summary

* badges: site navbar, embedding, theme, Forget move

* badges: use SB code prefix in web checkout

* badges: rename sxb app namespace to sb

* badges: embed checkout nav via site; keep original app navbar

* badges: post iframe height, apply site background when embedded

* badges: embed dark surfaces, steadier iframe height

* badges: hide app footer when embedded

* badges: size embedded body to content, not viewport

* badges: declare color-scheme to stop reload flash

* badges: fade shell in on load, no reload blank

* badges: prerender app shell into index.html

* badges: pre-paint theme, hide shell on deep reload

* badges: logo returns to landing client-side

* badges: embedded wizard back, buy-a-code, resume

* badges: signal app-managed screens, resume across reload

* badges: rebuild wizard history on deep load so Back walks it

* badges: carry welcome-page height as the iframe floor

* badges: keep selection on Buy a code; rename to Your codes

* badges: read web shell as UTF-8, not locale

* badges: resume the exact paid order after Stripe card redirect

* badges: move docker deploy under scripts

* badges: add serve_webapp toggle and webapp export

* badges: wire split webapp deploy in docker config

* badges: quiet agent logs by default

* badges: resume card redirect in the embedded frame

* badges: migrate Stripe adapter to PaymentIntents

* badges: correct Stripe restricted key scopes in ini example

* badges: card via Payment Element and PaymentIntents

* badges: fix stale Checkout Session wording in Stripe adapter

* badges: fix stale CheckoutActions reference in card comment

* badges: order shell stylesheet before bootstrap script

* badges: remove development card stand-in

* badges: theme the Stripe card form with the site palette

* badges: exclude web from the Haskell build stage

* badges: unify invoice cancel and mark canceled

* badges: default log level to info

* badges: unify closed-invoice buy-again button

* badges: mute agent connection logs at info level

* badges: show purchase time in local timezone in Your codes

* badges: log service events on own channel, quiet agent

* badges: fold service migrations into one baseline

* badges: run compose on postgres over host network

* badges: use high-res hero art

* badges: add web CI to catch stale builds

* badges: rebuild web shell from committed source

* badges: normalize invoice-code link and columns

* badges: drop unused columns, rename index

* badges: note deferred receipt_hash in migrations

* badges: apply code-review fixes

* badges: reduce comments across service and web

---------

Co-authored-by: Evgeny Poberezkin <evgeny@poberezkin.com>
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>

* badges: improve web page (#7546)

* badges: improve web page

* improve layout

* improve layout

* fix

* small changes

---------

Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>

* badges: read one issuer key from the ini

* badges: move and group the service tests

* badges: service fixes (#7567)

* badges: match the redeem error wording in tests

* badges: drop unused imports in the bot tests

* badges: cancel Stripe orders when they expire

* badges: correct the Stripe config and docs

* badges: refuse to revoke a redeemed code

* badges: make the fake Stripe cancel like Stripe

* badges: limit replayed webhook deliveries

---------

Co-authored-by: sh <37271604+shumvgolove@users.noreply.github.com>
Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
Co-authored-by: shum <github.shum@liber.li>
Co-authored-by: spaced4ndy <8711996+spaced4ndy@users.noreply.github.com>
2026-09-25 09:01:51 +00:00

50 lines
2.0 KiB
TypeScript

import assert from "node:assert/strict";
import { test } from "node:test";
import { RETURN_URL_MESSAGE, THEME_MESSAGE, returnUrlFromMessage, themeFromMessage, trustedHost } from "../src/embed.js";
test("embed: only https simplex.chat and its subdomains may drive the theme", () => {
for (const origin of ["https://simplex.chat", "https://www.simplex.chat", "https://badges.simplex.chat"]) {
assert.equal(trustedHost(origin), true, `${origin} is the site`);
}
for (const origin of [
"http://simplex.chat",
"https://simplex.chat.attacker.com",
"https://notsimplex.chat",
"https://evil.com",
"null",
"",
]) {
assert.equal(trustedHost(origin), false, `${origin} is not the site`);
}
});
test("embed: a theme message yields its theme, and anything else yields undefined", () => {
for (const theme of ["light", "dark", "system"]) {
assert.equal(themeFromMessage({ type: THEME_MESSAGE, theme }), theme, `${theme} is a theme`);
}
for (const data of [
{ type: "other", theme: "dark" },
{ type: THEME_MESSAGE, theme: "neon" },
{ type: THEME_MESSAGE },
{ theme: "dark" },
"dark", 42, null, undefined, [THEME_MESSAGE],
]) {
assert.equal(themeFromMessage(data), undefined, `${JSON.stringify(data)} carries no theme`);
}
});
test("embed: a return-url message yields a valid http(s) url, and anything else undefined", () => {
assert.equal(returnUrlFromMessage({ type: RETURN_URL_MESSAGE, url: "https://simplex.chat/badges/" }), "https://simplex.chat/badges/");
assert.equal(returnUrlFromMessage({ type: RETURN_URL_MESSAGE, url: "http://localhost:8001/badges/" }), "http://localhost:8001/badges/");
for (const bad of [
{ type: RETURN_URL_MESSAGE, url: "not a url" },
{ type: RETURN_URL_MESSAGE, url: "javascript:alert(1)" },
{ type: RETURN_URL_MESSAGE, url: 42 },
{ type: "simplex-theme", url: "https://simplex.chat/" },
null,
"https://simplex.chat/",
]) {
assert.equal(returnUrlFromMessage(bad), undefined, `${JSON.stringify(bad)} is not a return url`);
}
});