/**
 * xss-template-preview-sandbox smoke — the admin email-template preview must
 * render template.body inside a sandboxed iframe, never via
 * dangerouslySetInnerHTML.
 *
 * Why (security/xss, 2026-05-31): TemplateSettings previewed admin-authored
 * `template.body` with dangerouslySetInnerHTML, executing that HTML in the
 * dashboard origin (admin-only self-XSS). The fix renders it through
 * SafeHtmlPreview — an <iframe sandbox srcDoc> with NO allow-scripts. This
 * smoke statically guards that the dangerous path can't silently come back.
 */
import './_lib';
import { ok, fail } from './_lib';
import { readFileSync } from 'fs';
import path from 'path';

const ROOT = path.resolve(__dirname, '../..');
const read = (rel: string): string => readFileSync(path.join(ROOT, rel), 'utf8');

function assert(label: string, cond: boolean, detail: string): void {
    if (!cond) fail(label, detail);
    ok(label);
}

function main(): void {
    const tpl = read('src/components/settings/TemplateSettings.tsx');

    // 1. The preview no longer pipes template.body through dangerouslySetInnerHTML.
    assert('TemplateSettings drops dangerouslySetInnerHTML', !/dangerouslySetInnerHTML/.test(tpl),
        'TemplateSettings.tsx still uses dangerouslySetInnerHTML — admin template HTML executes in the dashboard origin.');

    // 2. It renders the body through the sandboxed SafeHtmlPreview instead.
    assert('TemplateSettings imports SafeHtmlPreview', /SafeHtmlPreview/.test(tpl),
        'TemplateSettings.tsx no longer uses SafeHtmlPreview for the body preview.');
    assert('SafeHtmlPreview receives template.body', /<SafeHtmlPreview[\s\S]*template\.body/.test(tpl),
        'TemplateSettings.tsx no longer feeds template.body into SafeHtmlPreview.');

    // 3. SafeHtmlPreview itself is an iframe with an empty (script-less) sandbox
    //    and carries the html via srcDoc (not into the parent DOM).
    const comp = read('src/components/ui/SafeHtmlPreview.tsx');
    assert('SafeHtmlPreview renders an iframe', /<iframe/.test(comp),
        'SafeHtmlPreview.tsx no longer renders an <iframe>.');
    // Inspect the sandbox attribute VALUE specifically (not the whole file —
    // doc comments legitimately mention the word "allow-scripts").
    const sandboxMatch = comp.match(/sandbox=(?:"([^"]*)"|\{[`'"]([^`'"]*)[`'"]\})/);
    const sandboxValue = sandboxMatch ? (sandboxMatch[1] ?? sandboxMatch[2] ?? '') : null;
    assert('SafeHtmlPreview iframe sets a sandbox attribute', sandboxValue !== null,
        'SafeHtmlPreview.tsx iframe has no sandbox attribute.');
    assert('SafeHtmlPreview sandbox does not grant allow-scripts', !/allow-scripts/.test(sandboxValue ?? ''),
        'SafeHtmlPreview.tsx sandbox grants allow-scripts — preview HTML could execute.');
    assert('SafeHtmlPreview uses srcDoc', /srcDoc=/.test(comp),
        'SafeHtmlPreview.tsx no longer feeds the html through srcDoc.');
    // Match the JSX PROP form so the explanatory doc comment (which names the
    // old API) doesn't trip this guard.
    assert('SafeHtmlPreview never uses dangerouslySetInnerHTML', !/dangerouslySetInnerHTML\s*=/.test(comp),
        'SafeHtmlPreview.tsx reintroduced dangerouslySetInnerHTML — defeats the sandbox.');

    ok('xss-template-preview-sandbox', 'admin template HTML preview is rendered inside a script-less sandboxed iframe, not dangerouslySetInnerHTML');
}

main();
