test(preload): ascii channel allow-list assertions + extend existing security test

Amit Haridas
This commit is contained in:
2026-09-14 20:55:58 +05:30
parent fecd23d35e
commit 1d68fc132f
2 changed files with 47 additions and 0 deletions
+41
View File
@@ -0,0 +1,41 @@
/**
* @jest-environment node
*
* Asserts that the preload.js allow-list contains the new ascii:* invoke
* channels and does NOT contain the dead show-ascii-generator* channels.
*/
const fs = require('fs');
const path = require('path');
const preloadSrc = fs.readFileSync(path.join(__dirname, '..', 'src', 'preload.js'), 'utf-8');
const REQUIRED_CHANNELS = [
'ascii:generate',
'ascii:list-fonts',
'ascii:get-font-meta',
'ascii:save',
'ascii:copy',
'ascii:last-font',
];
const DEAD_CHANNELS = ['show-ascii-generator', 'show-ascii-generator-window'];
describe('preload.js ASCII channels', () => {
test.each(REQUIRED_CHANNELS)('declares %s in the allow-list', (channel) => {
expect(preloadSrc).toContain(`'${channel}'`);
});
// DEFERRED to T11 — channels still in allow-list until T11 deletes them.
test.skip.each(DEAD_CHANNELS)('removed %s from allow-list', (channel) => {
expect(preloadSrc).not.toContain(`'${channel}'`);
});
test('generators.ascii namespace is exposed', () => {
expect(preloadSrc).toMatch(/ascii:\s*\{/);
expect(preloadSrc).toMatch(/listFonts/);
expect(preloadSrc).toMatch(/generate/);
expect(preloadSrc).toMatch(/copy/);
expect(preloadSrc).toMatch(/save/);
expect(preloadSrc).toMatch(/lastFont/);
});
});
+6
View File
@@ -51,6 +51,12 @@ describe('Preload Security', () => {
'get-pdf-page-count', 'get-pdf-page-count',
'select-pdf-folder', 'select-pdf-folder',
'open-ascii-generator', 'open-ascii-generator',
'ascii:generate',
'ascii:list-fonts',
'ascii:get-font-meta',
'ascii:save',
'ascii:copy',
'ascii:last-font',
'open-table-generator', 'open-table-generator',
'insert-generated-content', 'insert-generated-content',
'save-pasted-image', 'save-pasted-image',