From 8f6e1d4ff73cf5b123072caa412c6815ee631991 Mon Sep 17 00:00:00 2001 From: fabi Date: Wed, 1 Jul 2026 07:34:55 +0200 Subject: [PATCH] test(e2e): stored-XSS (caption/comment) + SSE-ticket abuse coverage MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Close two malicious-input gaps flagged in the suite review: XSS was only fuzzed through display_name, and the SSE ticket flow had no security assertions. xss-injection: - Stored XSS in captions — upload with each XSS payload as the caption, mark it feed-visible, render /feed and assert window.__xssFired stays false, no dialog fires, and no live `img[onerror]`/`