Release EPUB Tools 0.1.0

This commit is contained in:
2026-09-01 02:39:03 +02:00
commit f68dcfe4ea
66 changed files with 10579 additions and 0 deletions
+124
View File
@@ -0,0 +1,124 @@
import { expect, test, type Page } from "@playwright/test";
import {
TextReader,
Uint8ArrayReader,
Uint8ArrayWriter,
ZipWriter,
} from "@zip.js/zip.js";
const ORIGIN = "http://127.0.0.1:4173";
async function localOnly(page: Page) {
const external: string[] = [];
await page.route("**/*", async (route) => {
const url = new URL(route.request().url());
if (url.origin !== ORIGIN) {
external.push(url.href);
await route.abort();
} else await route.continue();
});
return external;
}
async function epubFixture(): Promise<Buffer> {
const writer = new ZipWriter(new Uint8ArrayWriter());
await writer.add("mimetype", new TextReader("application/epub+zip"), {
level: 0,
});
await writer.add(
"META-INF/container.xml",
new TextReader(
`<?xml version="1.0"?><container xmlns="urn:oasis:names:tc:opendocument:xmlns:container"><rootfiles><rootfile full-path="EPUB/package.opf" media-type="application/oebps-package+xml"/></rootfiles></container>`,
),
);
await writer.add(
"EPUB/package.opf",
new TextReader(
`<?xml version="1.0"?><package xmlns="http://www.idpf.org/2007/opf" version="3.0" unique-identifier="id"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/"><dc:identifier id="id">urn:browser:test</dc:identifier><dc:title>Browser Fixture</dc:title><dc:language>en</dc:language><dc:creator>Local Author</dc:creator></metadata><manifest><item id="nav" href="nav.xhtml" media-type="application/xhtml+xml" properties="nav"/><item id="chapter" href="chapter.xhtml" media-type="application/xhtml+xml"/><item id="cover" href="cover.png" media-type="image/png" properties="cover-image"/></manifest><spine><itemref idref="chapter"/></spine></package>`,
),
);
await writer.add(
"EPUB/nav.xhtml",
new TextReader(
`<?xml version="1.0"?><html xmlns="http://www.w3.org/1999/xhtml" xmlns:epub="http://www.idpf.org/2007/ops"><body><nav epub:type="toc"><ol><li><a href="chapter.xhtml">A safe chapter</a></li></ol></nav></body></html>`,
),
);
await writer.add(
"EPUB/chapter.xhtml",
new TextReader(
`<?xml version="1.0"?><html xmlns="http://www.w3.org/1999/xhtml"><head><title>A safe chapter</title></head><body><h1>Hello from EPUB</h1><script>document.body.textContent='unsafe'</script><img src="cover.png"/></body></html>`,
),
);
await writer.add(
"EPUB/cover.png",
new Uint8ArrayReader(
Buffer.from(
"iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mNk+A8AAQUBAScY42YAAAAASUVORK5CYII=",
"base64",
),
),
);
return Buffer.from(await writer.close());
}
test("runs from a nested path without external requests", async ({ page }) => {
const errors: string[] = [];
page.on("pageerror", (error) => errors.push(error.message));
page.on("console", (message) => {
if (message.type() === "error") errors.push(message.text());
});
const external = await localOnly(page);
await page.goto("/deep/nested/epub/");
await expect(page.getByRole("heading", { name: "EPUB Tools" })).toBeVisible();
expect(external).toEqual([]);
expect(errors).toEqual([]);
});
test("serves the release identity and hardened headers", async ({
request,
}) => {
const index = await request.get("/deep/nested/epub/");
expect(index.ok()).toBe(true);
expect(index.headers()["content-security-policy"]).toContain(
"default-src 'self'",
);
expect(await index.text()).not.toMatch(/\b(?:src|href)=["']\//u);
const manifest = await request.get("/deep/nested/epub/toolbox-app.json");
await expect(manifest.json()).resolves.toMatchObject({
id: "de.add-ideas.epub-tools",
version: "0.1.0",
entry: "./",
});
});
test("opens, sanitizes, edits, rebuilds, and reopens a real EPUB", async ({
page,
}) => {
const external = await localOnly(page);
await page.goto("/deep/nested/epub/");
await page.getByLabel("Choose EPUB").setInputFiles({
name: "fixture.epub",
mimeType: "application/epub+zip",
buffer: await epubFixture(),
});
await expect(
page.getByText("Browser Fixture", { exact: true }).first(),
).toBeVisible({ timeout: 30_000 });
const reader = page.frameLocator("iframe[title^='Safe EPUB preview']");
await expect(
reader.getByRole("heading", { name: "Hello from EPUB" }),
).toBeVisible();
await expect(reader.locator("script")).toHaveCount(0);
await page.getByRole("tab", { name: "Metadata" }).click();
await page.getByLabel("Title").fill("Updated in browser");
await page.getByRole("tab", { name: "Export & rebuild" }).click();
const downloadPromise = page.waitForEvent("download");
await page.getByRole("button", { name: "Create updated EPUB" }).click();
const download = await downloadPromise;
const path = await download.path();
expect(path).toBeTruthy();
await page.getByLabel("Open another").setInputFiles(path!);
await expect(
page.getByText("Updated in browser", { exact: true }).first(),
).toBeVisible({ timeout: 30_000 });
expect(external).toEqual([]);
});
+19
View File
@@ -0,0 +1,19 @@
import { render, screen } from "@testing-library/react";
import { describe, expect, it, vi } from "vitest";
import { App } from "../../src/App";
describe("EPUB Tools", () => {
it("renders the local workbench and standard shell", async () => {
vi.stubGlobal(
"fetch",
vi.fn(async () => new Response("Not found", { status: 404 })),
);
render(<App />);
expect(
await screen.findByRole("heading", { name: "EPUB Tools" }),
).toBeVisible();
expect(
await screen.findByText("Sandboxed reader · local files"),
).toBeVisible();
});
});
+114
View File
@@ -0,0 +1,114 @@
import { Blob as NodeBlob, File as NodeFile } from "node:buffer";
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
import { closeBook, openEpub } from "../../src/epub/archive";
import { patchPackageMetadata, rebuildEpub } from "../../src/epub/export";
import { resolvePackageHref, validateEntryPath } from "../../src/epub/paths";
import { renderChapter, revokeRenderedChapter } from "../../src/epub/reader";
import type { EpubBook } from "../../src/epub/types";
import { createEpubFixture } from "./fixture";
let opened: EpubBook[] = [];
beforeEach(() => {
vi.stubGlobal("Blob", NodeBlob);
vi.stubGlobal("File", NodeFile);
});
afterEach(async () => {
for (const book of opened) await closeBook(book);
opened = [];
vi.unstubAllGlobals();
});
describe("EPUB path policy", () => {
it("resolves package-relative references and rejects traversal", () => {
expect(
resolvePackageHref("EPUB/text/chapter.xhtml", "../images/cover.png#art"),
).toBe("EPUB/images/cover.png");
expect(() => resolvePackageHref("chapter.xhtml", "../outside")).toThrow(
/escapes/u,
);
expect(() => validateEntryPath("../escape")).toThrow(/traversal/u);
});
});
describe("EPUB package inspection", () => {
it("opens metadata, navigation, spine, and bounded inventory", async () => {
const book = await openEpub(await createEpubFixture());
opened.push(book);
expect(book.package.metadata).toMatchObject({
title: "Fixture Book",
language: "en",
identifier: "urn:test:book",
});
expect(book.package.navigation[0]).toMatchObject({
label: "Opening chapter",
path: "EPUB/chapter.xhtml",
});
expect(book.package.spine[0]?.item?.path).toBe("EPUB/chapter.xhtml");
expect(book.summary).toMatchObject({
mimetypeFirst: true,
mimetypeStored: true,
encryptedResources: false,
});
expect(book.issues.filter((item) => item.severity === "error")).toEqual([]);
});
it("reports active content and broken resources", async () => {
const book = await openEpub(
await createEpubFixture({ activeContent: true, brokenLink: true }),
);
opened.push(book);
expect(book.issues.map((item) => item.code)).toEqual(
expect.arrayContaining(["active-content", "broken-link"]),
);
});
});
describe("safe rendering and editing", () => {
it("removes active content, disables links, and resolves local images", async () => {
vi.stubGlobal("URL", {
...URL,
createObjectURL: vi.fn(() => "blob:fixture-cover"),
revokeObjectURL: vi.fn(),
});
const book = await openEpub(
await createEpubFixture({ activeContent: true }),
);
opened.push(book);
const chapter = await renderChapter(book, "EPUB/chapter.xhtml");
expect(chapter.html).not.toMatch(/<script|<form|<input/iu);
expect(chapter.html).toContain('src="blob:fixture-cover"');
expect(chapter.html).toContain('data-epub-href="nav.xhtml"');
expect(chapter.html).toContain("default-src 'none'");
revokeRenderedChapter(chapter);
});
it("patches metadata and rebuilds a readable normalized EPUB", async () => {
const book = await openEpub(await createEpubFixture());
opened.push(book);
const metadata = {
...book.package.metadata,
title: "Updated title",
creators: ["One", "Two"],
subjects: ["Testing"],
};
const xml = patchPackageMetadata(book.packageXml, metadata);
expect(xml).toContain("Updated title");
expect(xml.match(/<dc:creator/gu)).toHaveLength(2);
const rebuilt = await rebuildEpub(book, {
metadata,
normalizeTimestamps: true,
});
const reopened = await openEpub(
new File([rebuilt.blob], "rebuilt.epub", {
type: "application/epub+zip",
}),
);
opened.push(reopened);
expect(reopened.package.metadata.title).toBe("Updated title");
expect(reopened.package.metadata.creators).toEqual(["One", "Two"]);
expect(reopened.summary).toMatchObject({
mimetypeFirst: true,
mimetypeStored: true,
});
});
});
+51
View File
@@ -0,0 +1,51 @@
import {
BlobWriter,
TextReader,
Uint8ArrayReader,
ZipWriter,
} from "@zip.js/zip.js";
export async function createEpubFixture(
options: {
brokenLink?: boolean;
activeContent?: boolean;
compressedMimetype?: boolean;
} = {},
): Promise<File> {
const writer = new ZipWriter(new BlobWriter("application/epub+zip"));
await writer.add("mimetype", new TextReader("application/epub+zip"), {
level: options.compressedMimetype ? 6 : 0,
});
await writer.add(
"META-INF/container.xml",
new TextReader(
`<?xml version="1.0"?><container xmlns="urn:oasis:names:tc:opendocument:xmlns:container"><rootfiles><rootfile full-path="EPUB/package.opf" media-type="application/oebps-package+xml"/></rootfiles></container>`,
),
);
await writer.add(
"EPUB/package.opf",
new TextReader(
`<?xml version="1.0" encoding="UTF-8"?><package xmlns="http://www.idpf.org/2007/opf" version="3.0" unique-identifier="book-id"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/"><dc:identifier id="book-id">urn:test:book</dc:identifier><dc:title>Fixture Book</dc:title><dc:language>en</dc:language><dc:creator>Ada Example</dc:creator></metadata><manifest><item id="nav" href="nav.xhtml" media-type="application/xhtml+xml" properties="nav"/><item id="chapter" href="chapter.xhtml" media-type="application/xhtml+xml"/><item id="cover" href="cover.png" media-type="image/png" properties="cover-image"/></manifest><spine><itemref idref="chapter"/></spine></package>`,
),
);
await writer.add(
"EPUB/nav.xhtml",
new TextReader(
`<?xml version="1.0"?><html xmlns="http://www.w3.org/1999/xhtml" xmlns:epub="http://www.idpf.org/2007/ops"><head><title>Contents</title></head><body><nav epub:type="toc"><ol><li><a href="chapter.xhtml">Opening chapter</a></li></ol></nav></body></html>`,
),
);
await writer.add(
"EPUB/chapter.xhtml",
new TextReader(
`<?xml version="1.0"?><html xmlns="http://www.w3.org/1999/xhtml"><head><title>Opening chapter</title></head><body><h1>Hello</h1><p>Local reading.</p>${options.activeContent ? "<script>globalThis.pwned=true</script><form><input/></form>" : ""}<img src="cover.png"/><a href="${options.brokenLink ? "missing.xhtml" : "nav.xhtml"}">Next</a></body></html>`,
),
);
await writer.add(
"EPUB/cover.png",
new Uint8ArrayReader(
new Uint8Array([0x89, 0x50, 0x4e, 0x47, 0x0d, 0x0a, 0x1a, 0x0a]),
),
);
const blob = await writer.close();
return new File([blob], "fixture.epub", { type: "application/epub+zip" });
}