The property that drove the design: fmt reflection must not leak the raw bytes through any verb. Because Untrusted implements Stringer, %s, %v, and the Print family all route through String() and sanitize.
(t *testing.T)
| 20 | // bytes through any verb. Because Untrusted implements Stringer, %s, %v, and the |
| 21 | // Print family all route through String() and sanitize. |
| 22 | func TestUntrusted_fmt_paths_never_leak(t *testing.T) { |
| 23 | u := NewUntrusted("x" + esc + "]0;title" + esc + "\\") |
| 24 | cases := map[string]string{ |
| 25 | "%s": fmt.Sprintf("%s", u), |
| 26 | "%v": fmt.Sprintf("%v", u), |
| 27 | "Sprint": fmt.Sprint(u), |
| 28 | "woven": fmt.Sprintf("by %s here", u), |
| 29 | } |
| 30 | for name, out := range cases { |
| 31 | t.Run(name, func(t *testing.T) { |
| 32 | assert.NotContains(t, out, esc) |
| 33 | }) |
| 34 | } |
| 35 | } |
| 36 | |
| 37 | func TestUntrusted_Raw_returnsExactBytes(t *testing.T) { |
| 38 | payload := "x" + esc + "[1mbold" |
nothing calls this directly
no test coverage detected