@@ -22,6 +22,7 @@ import (
|
||||
func TestNoHTML(t *testing.T) {
|
||||
t.Run("valid text without HTML", func(t *testing.T) {
|
||||
str := "This is a normal text"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error, got: %v", err)
|
||||
@@ -30,6 +31,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("valid text with special characters", func(t *testing.T) {
|
||||
str := "Price: $10.99 - 20% off!"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error, got: %v", err)
|
||||
@@ -38,6 +40,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("valid UTF-8 text", func(t *testing.T) {
|
||||
str := "José García 张伟"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error, got: %v", err)
|
||||
@@ -46,6 +49,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("valid text with emojis", func(t *testing.T) {
|
||||
str := "Hello World 🌍"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error, got: %v", err)
|
||||
@@ -54,10 +58,12 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - script tag XSS", func(t *testing.T) {
|
||||
str := "<script>alert('xss')</script>"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for script tag")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "HTML tags") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -65,10 +71,12 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - simple bold tag", func(t *testing.T) {
|
||||
str := "Hello <b>World</b>"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for bold tag")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "HTML tags") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -76,6 +84,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - div tag", func(t *testing.T) {
|
||||
str := "<div>Content</div>"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for div tag")
|
||||
@@ -84,6 +93,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - self-closing tag", func(t *testing.T) {
|
||||
str := "Line break<br/>here"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for self-closing tag")
|
||||
@@ -92,6 +102,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - img tag", func(t *testing.T) {
|
||||
str := `<img src="x" onerror="alert(1)">`
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for img tag")
|
||||
@@ -100,6 +111,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - anchor tag", func(t *testing.T) {
|
||||
str := `<a href="javascript:alert(1)">Click</a>`
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for anchor tag")
|
||||
@@ -108,6 +120,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("valid - less than symbol", func(t *testing.T) {
|
||||
str := "5 < 10"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for bare angle bracket, got: %v", err)
|
||||
@@ -116,6 +129,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("valid - greater than symbol", func(t *testing.T) {
|
||||
str := "10 > 5"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for bare angle bracket, got: %v", err)
|
||||
@@ -124,6 +138,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("valid - both angle brackets", func(t *testing.T) {
|
||||
str := "5 < x > 10"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for bare angle brackets, got: %v", err)
|
||||
@@ -132,6 +147,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("valid - incomplete tag", func(t *testing.T) {
|
||||
str := "text <incomplete"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for incomplete tag, got: %v", err)
|
||||
@@ -140,6 +156,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - encoded attempt", func(t *testing.T) {
|
||||
str := "<ScRiPt>alert(1)</ScRiPt>"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for mixed case script tag")
|
||||
@@ -148,6 +165,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - svg onload XSS", func(t *testing.T) {
|
||||
str := `<svg onload=alert(1)>`
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for svg tag")
|
||||
@@ -156,6 +174,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - svg with slash", func(t *testing.T) {
|
||||
str := `<svg/onload=alert(1)>`
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for svg/onload tag")
|
||||
@@ -164,6 +183,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - iframe tag", func(t *testing.T) {
|
||||
str := `<iframe src="javascript:alert(1)">`
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for iframe tag")
|
||||
@@ -172,6 +192,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - style tag", func(t *testing.T) {
|
||||
str := `<style>body{background:url(evil)}</style>`
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for style tag")
|
||||
@@ -180,6 +201,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - HTML comment", func(t *testing.T) {
|
||||
str := `<!-- comment -->`
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for HTML comment")
|
||||
@@ -188,6 +210,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - DOCTYPE", func(t *testing.T) {
|
||||
str := `<!DOCTYPE html>`
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for DOCTYPE")
|
||||
@@ -196,6 +219,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - details ontoggle XSS", func(t *testing.T) {
|
||||
str := `<details open ontoggle=alert(1)>`
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for details tag")
|
||||
@@ -204,6 +228,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - body onload XSS", func(t *testing.T) {
|
||||
str := `<body onload=alert(1)>`
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for body tag")
|
||||
@@ -212,6 +237,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - object tag", func(t *testing.T) {
|
||||
str := `<object data="evil.swf">`
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for object tag")
|
||||
@@ -220,6 +246,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - embed tag", func(t *testing.T) {
|
||||
str := `<embed src="evil.swf">`
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for embed tag")
|
||||
@@ -228,6 +255,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - meta refresh", func(t *testing.T) {
|
||||
str := `<meta http-equiv="refresh" content="0;url=evil">`
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for meta tag")
|
||||
@@ -236,6 +264,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - input with autofocus XSS", func(t *testing.T) {
|
||||
str := `<input onfocus=alert(1) autofocus>`
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for input tag")
|
||||
@@ -244,6 +273,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("invalid - tag with newlines in attributes", func(t *testing.T) {
|
||||
str := "<img\nsrc=x\nonerror=alert(1)>"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for tag with newlines")
|
||||
@@ -252,6 +282,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("valid - math expression", func(t *testing.T) {
|
||||
str := "if x < 10 then y = 20"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for math expression, got: %v", err)
|
||||
@@ -260,6 +291,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("valid - arrow notation", func(t *testing.T) {
|
||||
str := "use -> or => for arrows"
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for arrow notation, got: %v", err)
|
||||
@@ -268,6 +300,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("empty string", func(t *testing.T) {
|
||||
str := ""
|
||||
|
||||
err := NoHTML()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for empty string, got: %v", err)
|
||||
@@ -276,6 +309,7 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("nil pointer", func(t *testing.T) {
|
||||
var str *string
|
||||
|
||||
err := NoHTML()(str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for nil, got: %v", err)
|
||||
@@ -284,10 +318,12 @@ func TestNoHTML(t *testing.T) {
|
||||
|
||||
t.Run("not a string", func(t *testing.T) {
|
||||
num := 123
|
||||
|
||||
err := NoHTML()(&num)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for non-string")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "must be a string") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -325,12 +361,14 @@ func TestNoHTML(t *testing.T) {
|
||||
// Should have error from NoHTML
|
||||
errors := v.Error().(ValidationErrors)
|
||||
found := false
|
||||
|
||||
for _, err := range errors {
|
||||
if strings.Contains(err.Message, "HTML tags") {
|
||||
found = true
|
||||
break
|
||||
}
|
||||
}
|
||||
|
||||
if !found {
|
||||
t.Error("expected error about HTML tags")
|
||||
}
|
||||
@@ -355,6 +393,7 @@ func TestNoHTML(t *testing.T) {
|
||||
func TestPrintableText(t *testing.T) {
|
||||
t.Run("valid UTF-8 text with accents", func(t *testing.T) {
|
||||
str := "José García"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for valid UTF-8 name, got: %v", err)
|
||||
@@ -363,6 +402,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("valid text with emojis", func(t *testing.T) {
|
||||
str := "Hello World 🌍"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for emojis, got: %v", err)
|
||||
@@ -371,6 +411,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("valid Chinese characters", func(t *testing.T) {
|
||||
str := "张伟"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for Chinese characters, got: %v", err)
|
||||
@@ -379,6 +420,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("valid Arabic text", func(t *testing.T) {
|
||||
str := "محمد"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for Arabic text, got: %v", err)
|
||||
@@ -387,6 +429,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("valid Cyrillic text", func(t *testing.T) {
|
||||
str := "Александр"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for Cyrillic text, got: %v", err)
|
||||
@@ -395,6 +438,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("valid text with apostrophe and hyphen", func(t *testing.T) {
|
||||
str := "O'Brien-Smith"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for apostrophe and hyphen, got: %v", err)
|
||||
@@ -403,6 +447,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("valid text with numbers", func(t *testing.T) {
|
||||
str := "Product 2024"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for text with numbers, got: %v", err)
|
||||
@@ -411,6 +456,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("valid text with punctuation", func(t *testing.T) {
|
||||
str := "Hello, World! How are you?"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for punctuation, got: %v", err)
|
||||
@@ -419,6 +465,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("valid text with angle brackets", func(t *testing.T) {
|
||||
str := "5 < 10 > 3"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for angle brackets (HTML checking is separate), got: %v", err)
|
||||
@@ -427,10 +474,12 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - RLO character", func(t *testing.T) {
|
||||
str := "test\u202Eexe.txt"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for RLO character")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "bidirectional override") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -438,6 +487,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - LRO character", func(t *testing.T) {
|
||||
str := "test\u202Dtext"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for LRO character")
|
||||
@@ -446,10 +496,12 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - zero-width space", func(t *testing.T) {
|
||||
str := "test\u200Btext"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for zero-width space")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "zero-width") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -457,6 +509,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - zero-width non-joiner", func(t *testing.T) {
|
||||
str := "test\u200Ctext"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for zero-width non-joiner")
|
||||
@@ -465,6 +518,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - zero-width joiner", func(t *testing.T) {
|
||||
str := "test\u200Dtext"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for zero-width joiner")
|
||||
@@ -473,6 +527,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - BOM character", func(t *testing.T) {
|
||||
str := "\uFEFFtest"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for BOM character")
|
||||
@@ -481,10 +536,12 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - null byte", func(t *testing.T) {
|
||||
str := "test\x00text"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for null byte")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "control character") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -492,6 +549,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - tab character", func(t *testing.T) {
|
||||
str := "test\ttext"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for tab character")
|
||||
@@ -500,6 +558,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("valid - newline character", func(t *testing.T) {
|
||||
str := "test\ntext"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for newline character, got: %v", err)
|
||||
@@ -508,6 +567,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("valid - carriage return", func(t *testing.T) {
|
||||
str := "test\rtext"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for carriage return, got: %v", err)
|
||||
@@ -516,6 +576,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("valid - multiple newlines", func(t *testing.T) {
|
||||
str := "hello foo\nbar\n\njd"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for multiple newlines, got: %v", err)
|
||||
@@ -524,10 +585,12 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - soft hyphen", func(t *testing.T) {
|
||||
str := "test\u00ADtext"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for soft hyphen")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "invisible formatting") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -535,6 +598,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - word joiner", func(t *testing.T) {
|
||||
str := "test\u2060text"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for word joiner")
|
||||
@@ -543,10 +607,12 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - private use area character", func(t *testing.T) {
|
||||
str := "test\uE000text"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for private use area")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "private use") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -554,10 +620,12 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - replacement character", func(t *testing.T) {
|
||||
str := "test\uFFFDtext"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for replacement character")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "replacement character") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -565,6 +633,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - DEL control character", func(t *testing.T) {
|
||||
str := "test\x7Ftext"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for DEL control character")
|
||||
@@ -573,6 +642,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - C1 control character", func(t *testing.T) {
|
||||
str := "test\u0080text"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for C1 control character")
|
||||
@@ -581,6 +651,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - LTR mark", func(t *testing.T) {
|
||||
str := "test\u200Etext"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for LTR mark")
|
||||
@@ -589,6 +660,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - RTL mark", func(t *testing.T) {
|
||||
str := "test\u200Ftext"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for RTL mark")
|
||||
@@ -597,6 +669,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("valid with pointer", func(t *testing.T) {
|
||||
str := "Valid Name"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error, got: %v", err)
|
||||
@@ -605,6 +678,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("empty string", func(t *testing.T) {
|
||||
str := ""
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for empty string, got: %v", err)
|
||||
@@ -613,6 +687,7 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("nil pointer", func(t *testing.T) {
|
||||
var str *string
|
||||
|
||||
err := PrintableText()(str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for nil, got: %v", err)
|
||||
@@ -621,10 +696,12 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("not a string", func(t *testing.T) {
|
||||
num := 123
|
||||
|
||||
err := PrintableText()(&num)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for non-string")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "must be a string") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -642,10 +719,12 @@ func TestPrintableText(t *testing.T) {
|
||||
|
||||
t.Run("position reported correctly", func(t *testing.T) {
|
||||
str := "abc\x00def"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "position 3") {
|
||||
t.Errorf("expected position 3 in error message, got: %s", err.Message)
|
||||
}
|
||||
@@ -655,10 +734,12 @@ func TestPrintableText(t *testing.T) {
|
||||
// Test that position is counted correctly with UTF-8 characters
|
||||
// The range loop in Go iterates by runes, so position will be rune index
|
||||
str := "abc\x00"
|
||||
|
||||
err := PrintableText()(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error")
|
||||
}
|
||||
|
||||
// The null byte is at rune position 3 (after 'a', 'b', 'c')
|
||||
if !strings.Contains(err.Message, "position 3") {
|
||||
t.Errorf("expected position 3 in error message, got: %s", err.Message)
|
||||
@@ -669,6 +750,7 @@ func TestPrintableText(t *testing.T) {
|
||||
func TestSafeText(t *testing.T) {
|
||||
t.Run("valid text", func(t *testing.T) {
|
||||
str := "Product Name 2024"
|
||||
|
||||
err := SafeText(100)(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error, got: %v", err)
|
||||
@@ -677,6 +759,7 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("valid UTF-8 text", func(t *testing.T) {
|
||||
str := "José García"
|
||||
|
||||
err := SafeText(50)(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error, got: %v", err)
|
||||
@@ -685,6 +768,7 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("valid text with emoji", func(t *testing.T) {
|
||||
str := "Hello World 🌍"
|
||||
|
||||
err := SafeText(50)(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error, got: %v", err)
|
||||
@@ -693,6 +777,7 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("valid text with apostrophe and hyphen", func(t *testing.T) {
|
||||
str := "O'Brien-Smith"
|
||||
|
||||
err := SafeText(50)(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error, got: %v", err)
|
||||
@@ -701,10 +786,12 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - empty string", func(t *testing.T) {
|
||||
str := ""
|
||||
|
||||
err := SafeText(100)(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for empty string")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "empty") && !strings.Contains(err.Message, "required") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -712,10 +799,12 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - exceeds max length", func(t *testing.T) {
|
||||
str := "This is a very long string that exceeds the maximum length"
|
||||
|
||||
err := SafeText(10)(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for exceeding max length")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "at most") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -723,10 +812,12 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - contains HTML tags", func(t *testing.T) {
|
||||
str := "Hello <b>World</b>"
|
||||
|
||||
err := SafeText(100)(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for HTML tags")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "HTML tags") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -734,6 +825,7 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - contains script tag", func(t *testing.T) {
|
||||
str := "<script>alert('xss')</script>"
|
||||
|
||||
err := SafeText(100)(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for script tag")
|
||||
@@ -742,6 +834,7 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("valid - contains angle brackets", func(t *testing.T) {
|
||||
str := "5 < 10"
|
||||
|
||||
err := SafeText(100)(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for bare angle brackets, got: %v", err)
|
||||
@@ -750,10 +843,12 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - contains null byte", func(t *testing.T) {
|
||||
str := "test\x00text"
|
||||
|
||||
err := SafeText(100)(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for null byte")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "control character") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -761,6 +856,7 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - contains tab character", func(t *testing.T) {
|
||||
str := "test\ttext"
|
||||
|
||||
err := SafeText(100)(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for tab character")
|
||||
@@ -769,6 +865,7 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("valid - contains newline", func(t *testing.T) {
|
||||
str := "test\ntext"
|
||||
|
||||
err := SafeText(100)(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for newline, got: %v", err)
|
||||
@@ -777,6 +874,7 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("valid - contains multiple newlines", func(t *testing.T) {
|
||||
str := "hello foo\nbar\n\njd"
|
||||
|
||||
err := SafeText(100)(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for multiple newlines, got: %v", err)
|
||||
@@ -785,10 +883,12 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - contains zero-width space", func(t *testing.T) {
|
||||
str := "test\u200Btext"
|
||||
|
||||
err := SafeText(100)(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for zero-width space")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "zero-width") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -796,10 +896,12 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - contains RLO character", func(t *testing.T) {
|
||||
str := "test\u202Eexe.txt"
|
||||
|
||||
err := SafeText(100)(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for RLO character")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "bidirectional override") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -807,10 +909,12 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("invalid - contains private use area character", func(t *testing.T) {
|
||||
str := "test\uE000text"
|
||||
|
||||
err := SafeText(100)(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for private use area")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "private use") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -818,6 +922,7 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("nil pointer", func(t *testing.T) {
|
||||
var str *string
|
||||
|
||||
err := SafeText(100)(str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for nil pointer, got: %v", err)
|
||||
@@ -826,10 +931,12 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("not a string", func(t *testing.T) {
|
||||
num := 123
|
||||
|
||||
err := SafeText(100)(&num)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for non-string")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "must be a string") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -856,12 +963,14 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
errors := v.Error().(ValidationErrors)
|
||||
found := false
|
||||
|
||||
for _, err := range errors {
|
||||
if strings.Contains(err.Message, "HTML tags") {
|
||||
found = true
|
||||
break
|
||||
}
|
||||
}
|
||||
|
||||
if !found {
|
||||
t.Error("expected error about HTML tags")
|
||||
}
|
||||
@@ -869,6 +978,7 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("edge case - exactly at max length", func(t *testing.T) {
|
||||
str := "12345"
|
||||
|
||||
err := SafeText(5)(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for string at max length, got: %v", err)
|
||||
@@ -877,6 +987,7 @@ func TestSafeText(t *testing.T) {
|
||||
|
||||
t.Run("edge case - one character over max length", func(t *testing.T) {
|
||||
str := "123456"
|
||||
|
||||
err := SafeText(5)(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for string over max length")
|
||||
@@ -887,6 +998,7 @@ func TestSafeText(t *testing.T) {
|
||||
func TestNoNewLine(t *testing.T) {
|
||||
t.Run("valid text without newlines", func(t *testing.T) {
|
||||
str := "Product Name 2024"
|
||||
|
||||
err := NoNewLine()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error, got: %v", err)
|
||||
@@ -895,10 +1007,12 @@ func TestNoNewLine(t *testing.T) {
|
||||
|
||||
t.Run("invalid - contains newline", func(t *testing.T) {
|
||||
str := "Line 1\nLine 2"
|
||||
|
||||
err := NoNewLine()(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for newline")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "newline") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -906,10 +1020,12 @@ func TestNoNewLine(t *testing.T) {
|
||||
|
||||
t.Run("invalid - contains carriage return", func(t *testing.T) {
|
||||
str := "Line 1\rLine 2"
|
||||
|
||||
err := NoNewLine()(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for carriage return")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "carriage return") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -917,6 +1033,7 @@ func TestNoNewLine(t *testing.T) {
|
||||
|
||||
t.Run("invalid - contains both newline and carriage return", func(t *testing.T) {
|
||||
str := "Line 1\n\rLine 3"
|
||||
|
||||
err := NoNewLine()(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for newline or carriage return")
|
||||
@@ -925,6 +1042,7 @@ func TestNoNewLine(t *testing.T) {
|
||||
|
||||
t.Run("nil pointer", func(t *testing.T) {
|
||||
var str *string
|
||||
|
||||
err := NoNewLine()(str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for nil pointer, got: %v", err)
|
||||
@@ -933,6 +1051,7 @@ func TestNoNewLine(t *testing.T) {
|
||||
|
||||
t.Run("empty string", func(t *testing.T) {
|
||||
str := ""
|
||||
|
||||
err := NoNewLine()(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for empty string, got: %v", err)
|
||||
@@ -943,6 +1062,7 @@ func TestNoNewLine(t *testing.T) {
|
||||
func TestSafeTextNoNewLine(t *testing.T) {
|
||||
t.Run("valid text", func(t *testing.T) {
|
||||
str := "Product Name 2024"
|
||||
|
||||
err := SafeTextNoNewLine(100)(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error, got: %v", err)
|
||||
@@ -951,6 +1071,7 @@ func TestSafeTextNoNewLine(t *testing.T) {
|
||||
|
||||
t.Run("valid UTF-8 text", func(t *testing.T) {
|
||||
str := "José García"
|
||||
|
||||
err := SafeTextNoNewLine(50)(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error, got: %v", err)
|
||||
@@ -959,10 +1080,12 @@ func TestSafeTextNoNewLine(t *testing.T) {
|
||||
|
||||
t.Run("invalid - contains newline", func(t *testing.T) {
|
||||
str := "Line 1\nLine 2"
|
||||
|
||||
err := SafeTextNoNewLine(100)(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for newline")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "newline") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -970,10 +1093,12 @@ func TestSafeTextNoNewLine(t *testing.T) {
|
||||
|
||||
t.Run("invalid - contains carriage return", func(t *testing.T) {
|
||||
str := "Line 1\rLine 2"
|
||||
|
||||
err := SafeTextNoNewLine(100)(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for carriage return")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "carriage return") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -981,10 +1106,12 @@ func TestSafeTextNoNewLine(t *testing.T) {
|
||||
|
||||
t.Run("invalid - empty string", func(t *testing.T) {
|
||||
str := ""
|
||||
|
||||
err := SafeTextNoNewLine(100)(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for empty string")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "empty") && !strings.Contains(err.Message, "required") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -992,10 +1119,12 @@ func TestSafeTextNoNewLine(t *testing.T) {
|
||||
|
||||
t.Run("invalid - exceeds max length", func(t *testing.T) {
|
||||
str := "This is a very long string that exceeds the maximum length"
|
||||
|
||||
err := SafeTextNoNewLine(10)(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for exceeding max length")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "at most") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -1003,10 +1132,12 @@ func TestSafeTextNoNewLine(t *testing.T) {
|
||||
|
||||
t.Run("invalid - contains HTML tags", func(t *testing.T) {
|
||||
str := "Hello <b>World</b>"
|
||||
|
||||
err := SafeTextNoNewLine(100)(&str)
|
||||
if err == nil {
|
||||
t.Fatal("expected validation error for HTML tags")
|
||||
}
|
||||
|
||||
if !strings.Contains(err.Message, "HTML tags") {
|
||||
t.Errorf("unexpected error message: %s", err.Message)
|
||||
}
|
||||
@@ -1014,6 +1145,7 @@ func TestSafeTextNoNewLine(t *testing.T) {
|
||||
|
||||
t.Run("invalid - contains tab character", func(t *testing.T) {
|
||||
str := "test\ttext"
|
||||
|
||||
err := SafeTextNoNewLine(100)(&str)
|
||||
if err == nil {
|
||||
t.Error("expected validation error for tab character")
|
||||
@@ -1022,6 +1154,7 @@ func TestSafeTextNoNewLine(t *testing.T) {
|
||||
|
||||
t.Run("nil pointer", func(t *testing.T) {
|
||||
var str *string
|
||||
|
||||
err := SafeTextNoNewLine(100)(str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for nil pointer, got: %v", err)
|
||||
@@ -1030,6 +1163,7 @@ func TestSafeTextNoNewLine(t *testing.T) {
|
||||
|
||||
t.Run("edge case - exactly at max length", func(t *testing.T) {
|
||||
str := "12345"
|
||||
|
||||
err := SafeTextNoNewLine(5)(&str)
|
||||
if err != nil {
|
||||
t.Errorf("expected no error for string at max length, got: %v", err)
|
||||
|
||||
Reference in New Issue
Block a user