
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
chai-a11y-axe
Advanced tools
This module provides a Chai plugin to perform automated accessibility tests via axe.
This package is shipped as a dependency with @open-wc/testing
so you do not need to install this seperately.
The BDD UI works with chai's expect
function.
Because the test is asynchronous, you must either await its result or pass a done
parameter in the plugin's options object.
You can ignore tags or ARIA rules, see configuration
import { fixture, expect, html } from '@open-wc/testing';
it('passes accessibility test', async () => {
const el = await fixture(html` <button>label</button> `);
await expect(el).to.be.accessible();
});
it('fails without label', async () => {
const el = await fixture(html` <div aria-labelledby="test-x"></div> `);
await expect(el).not.to.be.accessible();
});
it('passes for all rules, ignores attributes test', async () => {
const el = await fixture(html` <div aria-labelledby="test-x"></div> `);
await expect(el).to.be.accessible({
ignoredRules: ['aria-valid-attr-value'],
});
});
it('fails without alt attribute', async () => {
const el = await fixture(html` <img /> `);
await expect(el).not.to.be.accessible();
});
it('passes without alt attribute becuase img are ignored', async () => {
const el = await fixture(html` <img /> `);
await expect(el).not.to.be.accessible({
ignoredTags: ['img'],
});
});
it('accepts "done" option', done => {
fixture(html` <button>some light dom</button> `).then(el => {
expect(el).to.be.accessible({
done,
});
});
});
The isAccessible()
and isNotAccessible()
methods work on Chai's assert
function.
import { fixture, assert, html } from '@open-wc/testing';
it('passes axe accessible tests', async () => {
const el = await fixture(html` <button>some light dom</button> `);
await assert.isAccessible(el);
});
it('accepts ignored rules list', async () => {
const el = await fixture(html` <div aria-labelledby="test-x"></div> `);
await assert.isAccessible(el, {
ignoredRules: ['aria-valid-attr-value'],
});
});
it('passes for negation', async () => {
const el = await fixture(html` <div aria-labelledby="test-x"></div> `);
await assert.isNotAccessible(el);
});
ignoredRules
Rules can be ignored by passing ignoredRules
with a list of rules as a configuration option. e.g.: { ignoredRules: ['aria-valid-attr-value'] }
Here are all ARIA rules applied by axe-core. You will also find them in the violations report when running offending tests with this plugin.
This configuration option is passed down to axe-core
API so that the configured test will run with those rules disabled.
ignoredTags
Ignore elements with a specific tag by passing ignoredTags
with a list of tags to ignore. e.g.: { ignoredTags: ['img'] }
This configuration option will remove elements from the accessibility tree by setting the aria-hidden attribute for them.
FAQs
A11y tests for chai
The npm package chai-a11y-axe receives a total of 44,959 weekly downloads. As such, chai-a11y-axe popularity was classified as popular.
We found that chai-a11y-axe demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.