
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
@button-inc/relay-testing-library
Advanced tools
The ComponentTestingHelper
class provides the following:
environment
- the test relay environment to assert or configure the query generatorloadQuery(optional_resolver_override)
- preloads the Relay query for renderingrenderComponent()
renders the component with the react testing library - accessible through screen
expectMutationToBeCalled(mutation_name, variables_mutation_should_be_called with)
- checks if the expected mutation was called; optionally checks if it was called with the correct variablesrerenderComponent
- ??Create a jest test file called Component.test.tsx
In Component.test.tsx
, import the Component Testing Helper:
import ComponentTestingHelper from "@??";
Component.test.tsx
, import the component and mutation(s) you want to test:import Component from "path_to_component";
import Mutation from "path_to_mutation";
Component.test.tsx
, create a testQuery
.const testQuery = graphql`
# Add 'Test' before 'Query'
query ComponentTestQuery @relay_test_operation {
query {
# Spread the fragment you want to test here
...Component_query
}
}
`;
Run your relay compiler to create the ComponentTestQuery
In Component.test.tsx
, import
import ProjectContactForm from "components/Form/ProjectContactForm";
import compiledProjectContactFormQuery, {
ProjectContactFormQuery,
} from "__generated__/ProjectContactFormQuery.graphql";
import ComponentTestingHelper from "@TBD";
import ComponentUnderTest from "path_to_component";
import MutationUnderTest from "path_to_mutation";
import compiledComponetUnderTestQuery, {
ComponentTestingHelperQuery,
} from "./__generated__/ComponentTestingHelperQuery.graphql";
// The query mimics a page that contains that component,
// we craft a test query that uses the fragments of the component we're testing.
const testQuery = graphql`
query ProjectContactFormQuery @relay_test_operation {
query {
# Spread the fragment you want to test here
...ProjectContactForm_query
projectRevision(id: "Test Project Revision ID") {
...ProjectContactForm_projectRevision
}
}
}
`;
// This needs to match what we queried in our test query
const mockQueryPayload = {
ProjectRevision() {
const result: ProjectContactForm_projectRevision = {
" $fragmentType": "ProjectContactForm_projectRevision",
id: "Test Project Revision ID",
rowId: 1234,
... etc ...
};
return result;
},
Query() {
...
}
}
const defaultComponentProps = {
setValidatingForm: jest.fn(),
onSubmit: jest.fn(),
... etc ...
};
const componentTestingHelper =
new ComponentTestingHelper<ProjectContactFormQuery>({
component: ProjectContactForm,
testQuery: testQuery,
compiledQuery: compiledProjectContactFormQuery,
getPropsFromTestQuery: (data) => ({
// This is how to build the props for the component we're testing, based on our test query
query: data.query,
projectRevision: data.query.projectRevision,
}),
defaultQueryResolver: mockQueryPayload,
defaultQueryVariables: {},
// Additional default props for the component
defaultComponentProps: defaultComponentProps,
});
describe("the test suite", () => {
beforeEach(() => {
// reinit the helper before each test
componentTestingHelper.reinit();
});
it(...){
componentTestingHelper.loadQuery()
componentTestingHelper.renderComponent() // or if you need extra props for a particular test: componentTestingHelper.renderComponent(undefined, {...defaultComponentProps, extraProps })
... same testing as with the page helper ...
}
})
FAQs
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.