test_markupsafe.py 5.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208
  1. from __future__ import annotations
  2. import typing as t
  3. import pytest
  4. from markupsafe import escape
  5. from markupsafe import escape_silent
  6. from markupsafe import Markup
  7. from markupsafe import soft_str
  8. def test_adding() -> None:
  9. unsafe = '<script type="application/x-some-script">alert("foo");</script>'
  10. safe = Markup("<em>username</em>")
  11. assert unsafe + safe == str(escape(unsafe)) + str(safe)
  12. @pytest.mark.parametrize(
  13. ("template", "data", "expect"),
  14. (
  15. ("<em>%s</em>", "<bad user>", "<em>&lt;bad user&gt;</em>"),
  16. (
  17. "<em>%(username)s</em>",
  18. {"username": "<bad user>"},
  19. "<em>&lt;bad user&gt;</em>",
  20. ),
  21. ("%i", 3.14, "3"),
  22. ("%.2f", 3.14, "3.14"),
  23. ),
  24. )
  25. def test_string_interpolation(template: str, data: t.Any, expect: str) -> None:
  26. assert Markup(template) % data == expect
  27. def test_type_behavior() -> None:
  28. assert type(Markup("foo") + "bar") is Markup
  29. x = Markup("foo")
  30. assert x.__html__() is x
  31. def test_html_interop() -> None:
  32. class Foo:
  33. def __html__(self) -> str:
  34. return "<em>awesome</em>"
  35. def __str__(self) -> str:
  36. return "awesome"
  37. assert Markup(Foo()) == "<em>awesome</em>"
  38. result = Markup("<strong>%s</strong>") % Foo()
  39. assert result == "<strong><em>awesome</em></strong>"
  40. @pytest.mark.parametrize("args", ["foo", 42, ("foo", 42)])
  41. def test_missing_interpol(args: t.Any) -> None:
  42. with pytest.raises(TypeError):
  43. assert Markup("<em></em>") % args
  44. def test_tuple_interpol() -> None:
  45. result = Markup("<em>%s:%s</em>") % ("<foo>", "<bar>")
  46. expect = Markup("<em>&lt;foo&gt;:&lt;bar&gt;</em>")
  47. assert result == expect
  48. def test_dict_interpol() -> None:
  49. result = Markup("<em>%(foo)s</em>") % {"foo": "<foo>"}
  50. expect = Markup("<em>&lt;foo&gt;</em>")
  51. assert result == expect
  52. result = Markup("<em>%(foo)s:%(bar)s</em>") % {"foo": "<foo>", "bar": "<bar>"}
  53. expect = Markup("<em>&lt;foo&gt;:&lt;bar&gt;</em>")
  54. assert result == expect
  55. def test_escaping() -> None:
  56. assert escape("\"<>&'") == "&#34;&lt;&gt;&amp;&#39;"
  57. assert (
  58. Markup(
  59. "<!-- outer comment -->"
  60. "<em>Foo &amp; Bar"
  61. " <!-- inner comment about <em> -->\n "
  62. "</em>"
  63. "<!-- comment\nwith\nnewlines\n-->"
  64. "<meta content='tag\nwith\nnewlines'>"
  65. ).striptags()
  66. == "Foo & Bar"
  67. )
  68. def test_unescape() -> None:
  69. assert Markup("&lt;test&gt;").unescape() == "<test>"
  70. result = Markup("jack & tavi are cooler than mike &amp; russ").unescape()
  71. expect = "jack & tavi are cooler than mike & russ"
  72. assert result == expect
  73. original = "&foo&#x3b;"
  74. once = Markup(original).unescape()
  75. twice = Markup(once).unescape()
  76. expect = "&foo;"
  77. assert once == expect
  78. assert twice == expect
  79. def test_format() -> None:
  80. result = Markup("<em>{awesome}</em>").format(awesome="<awesome>")
  81. assert result == "<em>&lt;awesome&gt;</em>"
  82. result = Markup("{0[1][bar]}").format([0, {"bar": "<bar/>"}])
  83. assert result == "&lt;bar/&gt;"
  84. result = Markup("{0[1][bar]}").format([0, {"bar": Markup("<bar/>")}])
  85. assert result == "<bar/>"
  86. def test_format_map() -> None:
  87. result = Markup("<em>{value}</em>").format_map({"value": "<value>"})
  88. assert result == "<em>&lt;value&gt;</em>"
  89. def test_formatting_empty() -> None:
  90. formatted = Markup("{}").format(0)
  91. assert formatted == Markup("0")
  92. def test_custom_formatting() -> None:
  93. class HasHTMLOnly:
  94. def __html__(self) -> Markup:
  95. return Markup("<foo>")
  96. class HasHTMLAndFormat:
  97. def __html__(self) -> Markup:
  98. return Markup("<foo>")
  99. def __html_format__(self, spec: str) -> Markup:
  100. return Markup("<FORMAT>")
  101. assert Markup("{0}").format(HasHTMLOnly()) == Markup("<foo>")
  102. assert Markup("{0}").format(HasHTMLAndFormat()) == Markup("<FORMAT>")
  103. def test_complex_custom_formatting() -> None:
  104. class User:
  105. def __init__(self, id: int, username: str) -> None:
  106. self.id = id
  107. self.username = username
  108. def __html_format__(self, format_spec: str) -> Markup:
  109. if format_spec == "link":
  110. return Markup('<a href="/user/{0}">{1}</a>').format(
  111. self.id, self.__html__()
  112. )
  113. elif format_spec:
  114. raise ValueError("Invalid format spec")
  115. return self.__html__()
  116. def __html__(self) -> Markup:
  117. return Markup("<span class=user>{0}</span>").format(self.username)
  118. user = User(1, "foo")
  119. result = Markup("<p>User: {0:link}").format(user)
  120. expect = Markup('<p>User: <a href="/user/1"><span class=user>foo</span></a>')
  121. assert result == expect
  122. def test_formatting_with_objects() -> None:
  123. class Stringable:
  124. def __str__(self) -> str:
  125. return "строка"
  126. assert Markup("{s}").format(s=Stringable()) == Markup("строка")
  127. def test_escape_silent() -> None:
  128. assert escape_silent(None) == Markup()
  129. assert escape(None) == Markup(None)
  130. assert escape_silent("<foo>") == Markup("&lt;foo&gt;")
  131. def test_splitting() -> None:
  132. expect = [Markup("a"), Markup("b")]
  133. assert Markup("a b").split() == expect
  134. assert Markup("a b").rsplit() == expect
  135. assert Markup("a\nb").splitlines() == expect
  136. def test_mul() -> None:
  137. assert Markup("a") * 3 == Markup("aaa")
  138. def test_escape_return_type() -> None:
  139. assert isinstance(escape("a"), Markup)
  140. assert isinstance(escape(Markup("a")), Markup)
  141. class Foo:
  142. def __html__(self) -> str:
  143. return "<strong>Foo</strong>"
  144. assert isinstance(escape(Foo()), Markup)
  145. def test_soft_str() -> None:
  146. assert type(soft_str("")) is str # noqa: E721
  147. assert type(soft_str(Markup())) is Markup # noqa: E721
  148. assert type(soft_str(15)) is str # noqa: E721