Skip to content

test: gate redirect pages on what a browser decodes from make-redirects.sh output - #133

Merged
hivecommons-hive[bot] merged 1 commit into
mainfrom
quality/test-redirect-targets
Oct 7, 2026
Merged

hivecommons-hive[bot] merged 1 commit into
mainfrom
quality/test-redirect-targets

Conversation

@hivecommons-hive

Copy link
Copy Markdown
Contributor

Test Improvement

Adds scripts/redirect-targets.test.mjs, a static gate over what a browser actually makes of the shortcut-redirect pages that make-redirects.sh emits with the MAP url and label interpolated unescaped:

  • The MAP block parses; every entry has an absolute whitespace-free https?:// url and a label, and neither carries ", < or > (the template cannot escape them). A label that decodes as a character reference in text (Q&notify → &not) is rejected.
  • For every committed redirect page, the refresh url=, canonical href and <a href> are decoded under HTML attribute-value rules — numeric refs, &name;, and the 106 legacy no-semicolon names (&para, &reg, &copy, &not, …) with the tokenizer's =/alphanumeric quirk — and must equal the MAP url exactly; <title> and the link text are decoded under text rules and must equal the label.
  • Any other ambiguous ampersand on the page is reported; &amp; is the one accepted escape, so an escaping generator would pass just as well as today's raw &tmeid=…&tmsrc=… separators do.
  • Committed redirect pages and MAP paths must match one-to-one, and the generator template must still interpolate where the gate looks.

Each rule has a fixture self-test; zero dependencies. Picked up automatically by the existing node --test scripts/*.test.mjs CI step — no workflow change. README ## Checks documents the gate.

Verified locally at 7d6d8e1: full suite 314 → 338 pass. Mutation check: rewriting tv/index.html's target to end in &para fails only the new gate, naming all three attributes (browser decodes &para) plus three ambiguous-ampersand offsets; every pre-existing gate stays green on that mutation.

Closes #132


Filed by quality agent (ACMM L4/L6 — full mode)

— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

…ts.sh output

make-redirects.sh interpolates each MAP url and label into the refresh
url=, canonical href, <a href>, <title> and link text unescaped.
check-redirects.sh proves the page matches the generator and
check-links.sh curls the raw text, so a url ending in a legacy
no-semicolon entity (&para, &reg, &copy, ...) or a label with a quote or
angle bracket regenerates cleanly and ships a broken redirect.

Add scripts/redirect-targets.test.mjs: parse the MAP, reject
uninterpolatable url/label characters, decode every committed redirect
page's attributes under HTML attribute rules and its title/link text
under text rules, require each to resolve to the MAP entry, and report
any other ambiguous ampersand. Fixture self-tests for each rule; README
Checks entry.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: quality <quality@hive.kubestellar.io>
@kubestellar-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@hivecommons-hive
hivecommons-hive Bot merged commit c71f77e into main Oct 7, 2026
6 of 7 checks passed
@kubestellar-prow
kubestellar-prow Bot deleted the quality/test-redirect-targets branch October 7, 2026 22:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[quality] redirect pages: no gate decodes make-redirects.sh output as a browser would (legacy entities, attribute breakers)

0 participants