summaryrefslogtreecommitdiffstats
path: root/tests/test_messageview.cpp
diff options
context:
space:
mode:
authorDanilo M. <danix@danix.xyz>2026-08-07 17:51:52 +0200
committerDanilo M. <danix@danix.xyz>2026-08-07 17:51:52 +0200
commit334b510e2673a6ab3875ffa7a4c5b3b2dd09a369 (patch)
tree59b38af32af41d629a0c02ecd8e0fcfcddbb60e6 /tests/test_messageview.cpp
parent6003bab2d4c491a857b7a728f2f23c719723ef1a (diff)
downloadqtmaildir-334b510e2673a6ab3875ffa7a4c5b3b2dd09a369.tar.gz
qtmaildir-334b510e2673a6ab3875ffa7a4c5b3b2dd09a369.zip
feat(ui): fill the blank message pane with a branded placeholder
An empty right pane said nothing, and multi-select made it a routine sight. It now carries the wordmark, thread counts that run their query when clicked, and a sync line that appears only when something needs attention. Rendered into the existing web view as a third document shape, so there is one document path and one set of security rules. The brand palette is a deliberate exception to deriving colours from the desktop theme, since a logo is brand rather than chrome; the theme still picks which of the two sets is used. Counts refresh when the pane is about to show rather than in the background: one goes stale the moment a tag is edited, and refreshing one nobody is looking at is work for nothing. A generation counter discards a superseded reply, and a late answer cannot repaint over an opened thread. The helper lines are real links because JavaScript is off in this profile. The handler is gated on the placeholder actually being displayed, so the same URL inside a message body is dropped: a stranger's mail must not drive the thread list, even to run a harmless query. Three defects found while building, all silent: - Every CSS percentage was invalid. QString::arg does not collapse "%%" into "%", so the document carried "50%%" and the browser dropped each declaration holding one, disabling the mask, the glow and both radial gradients while still rendering something plausible. Substitution is by named token now, which cannot collide with a percent sign. - A geometry probe endorsed the layout while that was live, because it measured only properties without percentages. - The font test passed against a build with one face missing, since the other satisfied both of its checks on its own. The mockup's light values needed correcting against a real pane: the grid vanished at a 2% luminance step on white, and the glow subtracts light there rather than adding it, washing the pane. Strength only, not hue.
Diffstat (limited to 'tests/test_messageview.cpp')
-rw-r--r--tests/test_messageview.cpp74
1 files changed, 74 insertions, 0 deletions
diff --git a/tests/test_messageview.cpp b/tests/test_messageview.cpp
index 57d7b42..e94fb86 100644
--- a/tests/test_messageview.cpp
+++ b/tests/test_messageview.cpp
@@ -47,6 +47,8 @@ private slots:
void headerEscapesUntrustedValues();
void headerOmitsAnAbsentCc();
void detailsDialogIsOfferedForEveryThread();
+ void placeholderRendersAndReportsItself();
+ void aMessageBodyCannotRunAQuery();
private:
QWebEngineView *webViewOf(MessageView *view) const
@@ -492,5 +494,77 @@ void TestMessageView::detailsDialogIsOfferedForEveryThread()
QVERIFY(!button || !button->isVisible());
}
+void TestMessageView::placeholderRendersAndReportsItself()
+{
+ MessageView view;
+ QWebEngineView *web = webViewOf(&view);
+ QVERIFY(web);
+
+ QSignalSpy loaded(web, &QWebEngineView::loadFinished);
+ view.showPlaceholder({ { QStringLiteral("7 unread"),
+ QStringLiteral("tag:unread") } });
+
+ QVERIFY2(loaded.wait(15000), "the placeholder document never loaded");
+ QVERIFY2(loaded.last().at(0).toBool(),
+ "loadFinished reported failure: the navigation was rejected, "
+ "which is what a base-URL mismatch looks like");
+
+ // Rendered, not merely loaded. The wordmark is split across elements by
+ // the accent span, so the helper line is what proves the content arrived.
+ QString text;
+ bool done = false;
+ web->page()->toPlainText([&](const QString &result) {
+ text = result;
+ done = true;
+ });
+ QTRY_VERIFY_WITH_TIMEOUT(done, 15000);
+ QVERIFY2(text.contains(QStringLiteral("7 unread")), qPrintable(text));
+
+ QVERIFY(view.showingPlaceholder());
+}
+
+void TestMessageView::aMessageBodyCannotRunAQuery()
+{
+ // The gate behind queryRequested(). A message body is attacker-controlled
+ // HTML and can carry a qtmaildir-query: link; the view only honours one
+ // while the placeholder is what is displayed, so this asserts the state
+ // that decides it rather than synthesising a click, which would need the
+ // page's protected navigation handler.
+ MessageView view;
+ QSignalSpy queries(&view, &MessageView::queryRequested);
+
+ view.showPlaceholder({ { QStringLiteral("7 unread"),
+ QStringLiteral("tag:unread") } });
+ QVERIFY(view.showingPlaceholder());
+
+ ParsedMessage message;
+ message.ok = true;
+ message.from = QStringLiteral("Mallory <mallory@example.org>");
+ message.subject = QStringLiteral("Click me");
+ message.htmlBody = QStringLiteral(
+ "<a href=\"qtmaildir-query:tag%3Adeleted\">a link</a>");
+
+ ThreadRenderItem item;
+ item.message = message;
+ item.cidPrefix = QStringLiteral("m0");
+ item.expanded = true;
+
+ view.showThread({ item });
+
+ // Showing any message closes the gate, so a link in that message's own
+ // body has nothing to reach.
+ QVERIFY2(!view.showingPlaceholder(),
+ "the gate stayed open while a message was displayed: a link in a "
+ "message body could run a query");
+
+ view.clear();
+ QVERIFY(!view.showingPlaceholder());
+
+ view.showError(QStringLiteral("broken"), QStringLiteral("/tmp/x"));
+ QVERIFY(!view.showingPlaceholder());
+
+ QVERIFY(queries.isEmpty());
+}
+
QTEST_MAIN(TestMessageView)
#include "test_messageview.moc"