Skip to content

§15: re-vendor the XSS fixture test from the kit's node:test variant - #7

Merged
MichalAFerber merged 1 commit into
mainfrom
carrie/adopt-node-test-variant
Sep 7, 2026
Merged

MichalAFerber merged 1 commit into
mainfrom
carrie/adopt-node-test-variant

Conversation

@MichalAFerber

Copy link
Copy Markdown
Member

Refs MichalAFerber/tgwab-standards#129.

What

Replaces this repo's hand-ported test/xss-lint-fixture.test.js with templates/xss-lint-fixture-node.test.js from tgwab-standards v2.67.0. The blob now matches the template byte for byte.

Why this repo had a fork in the first place

The kit shipped only a vitest template, and this repo has no vitest — adding it for one file would have been a second test runner. So #4 ported the template to node:test. That port was correct: it carried all four controls (case1–case5 positives, both negative controls, the covers validation, the coverage assertion). It just matched no template version ever shipped, which §15 forbids, because the kit's 5-of-5 only means the same thing everywhere if the file is the same everywhere.

tgwab-standards v2.67.0 shipped a node:test variant seeded from this file. The port was right and the kit was missing. This vendors it back.

Scope

  • test/xss-lint-fixture.test.js — replaced with the template.
  • test/fixtures/xss-lint-fixture.js — already byte-identical, untouched.
  • test/fixtures/xss-lint-covers.json — this repo's own declaration, preserved unchanged. It is not part of the byte-identical kit, and its reasoning (naming html.js, core.js, common.js and explicitly not build/build.mjs) is good.

Nothing else changes.

Verified here, not assumed

✔ the XSS rule flags all five hazards ... (DS §15)
✔ the XSS rule leaves the two negative controls alone (DS §15)
DS §15 coverage: the rule resolves for 9 of 9 linted files; 3 named as product source.
✔ the rule resolves for every file this repo NAMES as covered product source (DS §15)
exit=0

Full npm test green — no regression to the repo's other tests.

Control, because a passing test that has never been seen to fail is not evidence: with no-restricted-syntax: 'off', all three tests go red (0 pass, 7 fail) and the run exits 1. So the rule genuinely reaches this repo, rather than the fixture passing through its synthetic path while covering nothing.

Acceptance

scripts/check-xss-kit-drift.sh currently reports this repo DRIFTED. After this merges it should read ok ... [xss-lint-fixture-node.test.js]. That checker is the acceptance test for this rollout, which is what it was built for.

🤖 Generated with Claude Code

https://claude.ai/code/session_016beCydw4C9VrgL9eHzGUG2

This repo's copy was a hand-port of the vitest template, written because the
kit shipped no node:test form and adding vitest for one file would have been a
second runner. The port was right — it carried all four controls — but it
matched no template version ever shipped, and §15 requires the kit to be
byte-identical across adopters so its 5-of-5 means the same thing everywhere.

tgwab-standards v2.67.0 shipped templates/xss-lint-fixture-node.test.js, seeded
from this very file. Vendoring it back closes the divergence: the blob now
matches the template exactly, and scripts/check-xss-kit-drift.sh accepts it.

test/fixtures/xss-lint-fixture.js was already byte-identical and is untouched.
The covers declaration is this repo's own and is preserved unchanged.

Verified here, not assumed: 3 of 3 pass, coverage reports the rule resolving for
9 of 9 linted files with 3 named as product source, and the full suite is green.
Control: with no-restricted-syntax switched off all three tests go red (0 pass,
7 fail), so the rule is genuinely reaching this repo rather than the fixture
passing on a synthetic path alone.

Refs MichalAFerber/tgwab-standards#129

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016beCydw4C9VrgL9eHzGUG2
@MichalAFerber
MichalAFerber marked this pull request as ready for review September 7, 2026 08:08
@MichalAFerber
MichalAFerber merged commit c7f4561 into main Sep 7, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant