// TEST VECTORS for the social icon checker (socialSvg.ts) and its render path — // test data only, imported by common/lib/normalizeSocialSvg.test.ts and the // homepage e2e (svg-vectors.spec.ts, social.spec.ts). Synthetic throughout. // // ADVERSARIAL: the review's battery (release 14, slice HP): every input the // checker must either refuse or render inertly — no script, no request to // another origin, and the page parsed around the icon unchanged. // LOADS_ELSEWHERE: the eight the first allowlist accepted that made Chromium // fetch from another origin (R2); all refused now. // REAL_SHAPES: the shapes an operator's pasted icons take; each must pass, or // that icon turns into a text label on every site. const V = `viewBox="0 0 8 8"`; const W = (inner: string, open = ``) => `${open}${inner}`; export const EVIL = "https://evil.example"; export const ADVERSARIAL: Record = { // the five originals slash_handler: ``, deletion_join: ``, image_slash: W(``), charref_js: W(``), breakout_img: W(``), // tokenizer unterminated_tag: ``, unterminated_quote: ``, handler_no_value: ``, dup_href_first_ok: W(``), dup_href_first_bad: W(``), dup_fill: W(``), upper_xlink: W(``), upper_xlink_frag: W(``), xml_base: ``, xmlns_redef: ``, xmlns_js: ``, nul_in_name: ``, nul_in_value: ``, vt_separator: ``, cr_separator: ``, no_ws_between_attrs: ``, backtick_value: ``, unquoted_value: ``, gt_in_dq_value: ``, gt_in_sq_value: ``, sq_value_with_fill: ``, // entities ent_leading_zeros: W(``), ent_hex_nosemi: W(``), ent_colon_tab_nl: W(``), ent_colon_nosemi: W(``), href_ent_hash: W(``), href_ws_frag: W(``), // css url forms style_url_escape: W(``), style_comment_url: W(``), pres_url_escape_fill: W(``), pres_url_escape_filter: W(``), pres_url_escape_mask: W(``), pres_url_escape_clip: W(``), pres_mask_imageset: W(``), style_bg_imageset_root: ``, style_mask_imageset: W(``), style_cursor_imageset: ``, style_webkit_imageset: ``, anim_fill_escape: W(``), anim_mask_imageset: W(``), anim_style: W(``), // references use_external: W(``), use_data: W(``), feimage: W(``), anchor: W(``), anim_href: W(``), anim_href_ws: W(``), anim_xlink_prefix: ``, anim_onclick: W(``), anim_xlink_onclick: W(``), // elements style_el: W(``), nested_svg: W(``), title_markup_text: W(`<img src=x onerror=window.__x=1>`), title_child_el: W(``), desc_child_el: W(``), title_title: W(`<title>x`), title_svg_title: W(`<svg viewBox="0 0 1 1"><title>t`), math: W(`x`), table: W(`
x
`), after_root_html: ``, after_root_ws: `\n `, doctype_subset: `]>`, doctype_plain: ``, doctype_html: ``, xmldecl_gt: `b"?>`, comment_join: `ipt>window.__x=1`, comment_bang_close: ` -->`, comment_abrupt: `-->`, cdata: W(`]]>`), pi: W(``), upper_close: ``, close_ws: ``, close_attr: ``, svg_ns_script: W(`window.__x=1`), // layout / redress (not script) overlay_style: ``, class_redress: ``, id_clobber: W(``), role_aria: ``, }; export const LOADS_ELSEWHERE: readonly string[] = [ "pres_url_escape_mask", "pres_url_escape_clip", "pres_mask_imageset", "style_bg_imageset_root", "style_mask_imageset", "style_cursor_imageset", "style_webkit_imageset", "anim_mask_imageset", ]; export const REAL_SHAPES: Record = { // A gradient body with a dark outline under it, the root as a drawing // program writes it. gradient_outlined: `` + `` + `` + `` + ``, // One path in the link's colour, `fill="none"` on the root. single_path: ``, // A two-colour disc with a stroke on the disc and a decimal viewBox. disc_stroked: `` + `` + `` + ``, };