/**
* The review body renderer, against hostile relay content.
*
* `lib/review-body.ts` is deliberately import-free so this file can load it under
* plain node with type stripping: `pnpm test` (node --experimental-strip-types).
* If these fail, an event someone can sign today can break or script the card.
*/
import test from 'node:test';
import assert from 'node:assert/strict';
import { escapeHtml, reviewBodyHtml } from '../src/lib/review-body.ts';
import { HOSTILE_REVIEW_CONTENT, LONG_URL, PASTED_NPUB } from './hostile-review.mjs';
/** The output with this module's own elements removed: nothing else may be markup. */
function withoutOwnLinks(html) {
return html.replace(/]*>.*?<\/a>/gs, '');
}
test('the hostile fixture renders with no live markup', () => {
const html = reviewBodyHtml(HOSTILE_REVIEW_CONTENT);
const rest = withoutOwnLinks(html);
assert.ok(!rest.includes('<'), `unescaped markup survived: ${rest.slice(0, 200)}`);
assert.ok(html.includes('<script>'), 'script tag must render as text');
assert.ok(!/
|