import { describe, expect, test } from "bun:test" import { OauthCallbackPage } from "../src/oauth/page" describe("OauthCallbackPage", () => { test("escapes bootstrap options embedded in the inline script", () => { const html = OauthCallbackPage.bootstrap({ provider: `xAI`, tokenPath: `/token`, }) expect(html.match(/<\/script>/g)).toHaveLength(1) expect(html).toContain(`xAI\\u003c/script>\\u003cscript>alert(\\\"provider\\\")\\u003c/script>`) expect(html).toContain(`/token\\u003c/script>\\u003cscript>alert(\\\"path\\\")\\u003c/script>`) }) })