/** * The review body renderer, against hostile relay content. * * `lib/review-body.ts` is deliberately import-free so this file can load it under * plain node with type stripping: `pnpm test` (node --experimental-strip-types). * If these fail, an event someone can sign today can break or script the card. */ import test from 'node:test'; import assert from 'node:assert/strict'; import { escapeHtml, reviewBodyHtml } from '../src/lib/review-body.ts'; import { HOSTILE_REVIEW_CONTENT, LONG_URL, PASTED_NPUB } from './hostile-review.mjs'; /** The output with this module's own elements removed: nothing else may be markup. */ function withoutOwnLinks(html) { return html.replace(/]*>.*?<\/a>/gs, ''); } test('the hostile fixture renders with no live markup', () => { const html = reviewBodyHtml(HOSTILE_REVIEW_CONTENT); const rest = withoutOwnLinks(html); assert.ok(!rest.includes('<'), `unescaped markup survived: ${rest.slice(0, 200)}`); assert.ok(html.includes('<script>'), 'script tag must render as text'); assert.ok(!/|