Commit c47b1e6e6c

c47b1e6e6cbff399dc7f5e60d2bae162e4cba511

parent: e6258f1dc1

Unsigned

cmc <hello@cleberg.net> · 2026-07-16 00:22 UTC

test: assert image URLs are not double-escaped

markdownImageQueryStringPreservesAmpersands rejected any "amp;metric" in the
rendered HTML, but `&amp;` is the correct encoding for `&` in an attribute
value and is what a browser needs to request a literal `&`. The assertion
conflated the URL with its HTML encoding.

Target the real failure mode instead: double-escaping, which would send
"&amp;" through as part of the query string and break badge images.

Layout: unified · split

HutchTests/ReadmeViewTests.swift +4 −1
@@ -179,8 +179,11 @@ struct MarkdownRenderingTests {
179179 func markdownImageQueryStringPreservesAmpersands() {
180180 let html = processInline("![badge](https://sonarcloud.io/api/project_badges/measure?project=ccleberg_Hutch&metric=security_rating)")
181181
182 // `&amp;` is the correct encoding for `&` in an attribute value, so the
183 // failure mode to guard against is double-escaping, which would make the
184 // browser request a literal "&amp;" in the query string.
182185 #expect(html.contains("metric=security_rating"))
183 #expect(!html.contains("amp;metric"))
186 #expect(!html.contains("&amp;amp;"))
184187 #expect(html.contains("<img"))
185188 }
186189