test(e2e): address self-review follow-ups (dedup, XSS render guard, SSE hardening)
Follow-ups from the code review of the test-quality batches: - Consolidate duplicated helpers into e2e/helpers/: seed.ts (seedUpload, seedComment, listComments, findFeedRow) and sse.ts (mintSseTicket, openStream, trackStreamOpens). Refactor authorization-deep, xss-injection, like-comment, sse-ticket-abuse, ddos, sse-realtime, multi-tab, and SseListener to use them — the upload/comment/ticket-flow contracts now live in one place each instead of being re-inlined across 3–7 specs. - xss-injection display-name loop: it navigated to /feed (which renders uploader names, not the viewer's) so "nothing fired" passed vacuously — the payload was never rendered. Now navigate to /account (the actual sink) and add a render guard asserting the payload reached the DOM as escaped text before checking __xssFired. - sse-realtime reconnect: snapshot the stream-open count AFTER backgrounding, so the "new connection" assertion is attributable to the foreground event and can't be satisfied by a spurious native/error reconnect before the toggle. - recover-page: correct the comment (auto-submit is the onPinInput handler, not an $effect). 44 affected specs verified green. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -4,6 +4,7 @@
|
||||
* or rejected gracefully without crashing the backend.
|
||||
*/
|
||||
import { test, expect } from '../../fixtures/test';
|
||||
import { mintSseTicket } from '../../helpers/sse';
|
||||
|
||||
const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101';
|
||||
|
||||
@@ -48,15 +49,9 @@ test.describe('Adversarial — small-scale abuse', () => {
|
||||
const g = await guest('SseFlood');
|
||||
// The stream endpoint authenticates via single-use tickets (POST /stream/ticket),
|
||||
// not the raw JWT — a `?token=` open is rejected with 400. Mint one ticket per stream.
|
||||
const mintTicket = async () => {
|
||||
const res = await fetch(`${BASE}/api/v1/stream/ticket`, {
|
||||
method: 'POST',
|
||||
headers: { Authorization: `Bearer ${g.jwt}` },
|
||||
});
|
||||
const json: any = await res.json();
|
||||
return json.ticket as string;
|
||||
};
|
||||
const tickets = await Promise.all(Array.from({ length: 10 }, mintTicket));
|
||||
// (These streams must be held open concurrently, so we can't use the openStream
|
||||
// helper which opens-and-aborts a single stream.)
|
||||
const tickets = await Promise.all(Array.from({ length: 10 }, () => mintSseTicket(g.jwt)));
|
||||
|
||||
const controllers = tickets.map(() => new AbortController());
|
||||
const requests = tickets.map((ticket, i) =>
|
||||
|
||||
Reference in New Issue
Block a user