From 63d0491b161457913c938d620dc1f26f29c798a9 Mon Sep 17 00:00:00 2001 From: Christian Cleberg Date: Wed, 15 Jul 2026 19:22:12 -0500 Subject: test: assert image URLs are not double-escaped markdownImageQueryStringPreservesAmpersands rejected any "amp;metric" in the rendered HTML, but `&` is the correct encoding for `&` in an attribute value and is what a browser needs to request a literal `&`. The assertion conflated the URL with its HTML encoding. Target the real failure mode instead: double-escaping, which would send "&" through as part of the query string and break badge images. --- HutchTests/ReadmeViewTests.swift | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/HutchTests/ReadmeViewTests.swift b/HutchTests/ReadmeViewTests.swift index 3b9d80b..08e602d 100644 --- a/HutchTests/ReadmeViewTests.swift +++ b/HutchTests/ReadmeViewTests.swift @@ -179,8 +179,11 @@ struct MarkdownRenderingTests { func markdownImageQueryStringPreservesAmpersands() { let html = processInline("![badge](https://sonarcloud.io/api/project_badges/measure?project=ccleberg_Hutch&metric=security_rating)") + // `&` is the correct encoding for `&` in an attribute value, so the + // failure mode to guard against is double-escaping, which would make the + // browser request a literal "&" in the query string. #expect(html.contains("metric=security_rating")) - #expect(!html.contains("amp;metric")) + #expect(!html.contains("&")) #expect(html.contains("