chore: import upstream snapshot with attribution
Deploy Site / deploy-vercel (push) Has been skipped
Deploy Site / deploy-docs (push) Has been skipped
Build Skills Index / build-index (push) Has been skipped
CI / Deny unrelated histories (push) Has been skipped
CI / Detect affected areas (push) Successful in 27m35s
CI / OSV scan (push) Failing after 4s
CI / Build&Test Docker image (push) Successful in 9s
CI / Supply-chain scan (push) Has been skipped
CI / Lint Docker scripts (push) Failing after 5m13s
CI / Check contributors (push) Failing after 12m8s
CI / Docs Site (push) Failing after 12m8s
CI / TypeScript (push) Failing after 12m8s
CI / Python lints (push) Failing after 12m9s
CI / Python tests (push) Failing after 12m9s
CI / Check uv.lock (push) Failing after 23m22s
CI / CI timing report (push) Has been cancelled
Build Skills Index / trigger-deploy (push) Has been cancelled
CI / All required checks pass (push) Has been cancelled
Deploy Site / deploy-vercel (push) Has been skipped
Deploy Site / deploy-docs (push) Has been skipped
Build Skills Index / build-index (push) Has been skipped
CI / Deny unrelated histories (push) Has been skipped
CI / Detect affected areas (push) Successful in 27m35s
CI / OSV scan (push) Failing after 4s
CI / Build&Test Docker image (push) Successful in 9s
CI / Supply-chain scan (push) Has been skipped
CI / Lint Docker scripts (push) Failing after 5m13s
CI / Check contributors (push) Failing after 12m8s
CI / Docs Site (push) Failing after 12m8s
CI / TypeScript (push) Failing after 12m8s
CI / Python lints (push) Failing after 12m9s
CI / Python tests (push) Failing after 12m9s
CI / Check uv.lock (push) Failing after 23m22s
CI / CI timing report (push) Has been cancelled
Build Skills Index / trigger-deploy (push) Has been cancelled
CI / All required checks pass (push) Has been cancelled
This commit is contained in:
@@ -0,0 +1,56 @@
|
||||
import re
|
||||
|
||||
from hermes_cli.session_export_html import _generate_messages_html
|
||||
|
||||
|
||||
def test_tool_call_name_is_escaped_in_html_export():
|
||||
messages = [
|
||||
{
|
||||
"role": "assistant",
|
||||
"content": "",
|
||||
"timestamp": 1700000000,
|
||||
"tool_calls": [
|
||||
{
|
||||
"function": {
|
||||
"name": "<script>alert(1)</script>",
|
||||
"arguments": "{}",
|
||||
}
|
||||
}
|
||||
],
|
||||
}
|
||||
]
|
||||
|
||||
html = _generate_messages_html(messages)
|
||||
|
||||
# Raw, executable markup must never reach the standalone artifact.
|
||||
assert "<script>alert(1)</script>" not in html
|
||||
# The escaped form must be present instead.
|
||||
assert "<script>alert(1)</script>" in html
|
||||
|
||||
|
||||
def test_role_is_escaped_in_html_export():
|
||||
messages = [
|
||||
{
|
||||
"role": "<img src=x onerror=alert(document.domain)>",
|
||||
"content": "hello",
|
||||
"timestamp": 1700000000,
|
||||
}
|
||||
]
|
||||
|
||||
html = _generate_messages_html(messages)
|
||||
|
||||
assert "<img src=x onerror=alert(document.domain)>" not in html
|
||||
assert "<img src=x onerror=alert(document.domain)>" in html
|
||||
# The class attribute must remain a single, well-formed token: a crafted
|
||||
# role must not break out of it nor split into several unintended classes.
|
||||
class_value = re.search(r'class="(message message-[^"]*active)"', html)
|
||||
assert class_value is not None
|
||||
assert " message-" in class_value.group(1) # exactly one message-<role> class
|
||||
assert class_value.group(1).count("message-") == 1
|
||||
|
||||
|
||||
def test_known_role_keeps_its_css_class():
|
||||
html = _generate_messages_html(
|
||||
[{"role": "assistant", "content": "hi", "timestamp": 1700000000}]
|
||||
)
|
||||
assert 'class="message message-assistant active"' in html
|
||||
Reference in New Issue
Block a user