diff --git a/e2e/specs/07-adversarial/sse-ticket-abuse.spec.ts b/e2e/specs/07-adversarial/sse-ticket-abuse.spec.ts new file mode 100644 index 0000000..1750887 --- /dev/null +++ b/e2e/specs/07-adversarial/sse-ticket-abuse.spec.ts @@ -0,0 +1,61 @@ +/** + * Phase 2 adversarial — SSE ticket capability abuse. + * + * The stream endpoint authenticates via short-lived, single-use tickets minted at + * POST /api/v1/stream/ticket (never the raw JWT in the URL). These tests pin the + * security properties of that flow: minting requires auth, and a ticket is consumed + * on first use so it cannot be replayed. + */ +import { test, expect } from '../../fixtures/test'; + +const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101'; + +async function mintTicket(jwt: string): Promise { + const res = await fetch(`${BASE}/api/v1/stream/ticket`, { + method: 'POST', + headers: { Authorization: `Bearer ${jwt}` }, + }); + if (res.status !== 200) throw new Error(`mint failed: ${res.status} ${await res.text()}`); + return (await res.json()).ticket; +} + +/** Open the SSE stream with a ticket, return the HTTP status, and tear the stream down. */ +async function openStream(ticket: string): Promise { + const c = new AbortController(); + try { + const res = await fetch(`${BASE}/api/v1/stream?ticket=${encodeURIComponent(ticket)}`, { + signal: c.signal, + }); + return res.status; + } finally { + c.abort(); + } +} + +test.describe('Adversarial — SSE ticket abuse', () => { + test('minting a ticket requires authentication', async () => { + const res = await fetch(`${BASE}/api/v1/stream/ticket`, { method: 'POST' }); + expect(res.status).toBe(401); + }); + + test('a ticket is single-use: replay after first open is rejected', async ({ guest }) => { + const g = await guest('SseReplay'); + const ticket = await mintTicket(g.jwt); + + // First open consumes the ticket. + expect(await openStream(ticket)).toBe(200); + + // Replaying the exact same ticket must fail — it was consumed, so `consume` returns + // None → 401. A 200 here would mean tickets are reusable (capability replay). + expect(await openStream(ticket)).toBe(401); + }); + + test('an unminted / garbage ticket is rejected', async () => { + // 24-byte-shaped hex string that was never issued. + const bogus = 'deadbeef'.repeat(6); + expect(await openStream(bogus)).toBe(401); + }); + // Note: the replay test's first open (→ 200) already proves a freshly-minted ticket + // works, so there is no separate "fresh ticket" sanity test — a second successful open + // would just add ~30s (SSE headers flush on the keep-alive tick through Caddy). +}); diff --git a/e2e/specs/07-adversarial/xss-injection.spec.ts b/e2e/specs/07-adversarial/xss-injection.spec.ts index 701f789..4489950 100644 Binary files a/e2e/specs/07-adversarial/xss-injection.spec.ts and b/e2e/specs/07-adversarial/xss-injection.spec.ts differ