test(e2e): address self-review follow-ups (dedup, XSS render guard, SSE hardening)
Follow-ups from the code review of the test-quality batches: - Consolidate duplicated helpers into e2e/helpers/: seed.ts (seedUpload, seedComment, listComments, findFeedRow) and sse.ts (mintSseTicket, openStream, trackStreamOpens). Refactor authorization-deep, xss-injection, like-comment, sse-ticket-abuse, ddos, sse-realtime, multi-tab, and SseListener to use them — the upload/comment/ticket-flow contracts now live in one place each instead of being re-inlined across 3–7 specs. - xss-injection display-name loop: it navigated to /feed (which renders uploader names, not the viewer's) so "nothing fired" passed vacuously — the payload was never rendered. Now navigate to /account (the actual sink) and add a render guard asserting the payload reached the DOM as escaped text before checking __xssFired. - sse-realtime reconnect: snapshot the stream-open count AFTER backgrounding, so the "new connection" assertion is attributable to the foreground event and can't be satisfied by a spurious native/error reconnect before the toggle. - recover-page: correct the comment (auto-submit is the onPinInput handler, not an $effect). 44 affected specs verified green. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -7,31 +7,10 @@
|
||||
* on first use so it cannot be replayed.
|
||||
*/
|
||||
import { test, expect } from '../../fixtures/test';
|
||||
import { mintSseTicket, openStream } from '../../helpers/sse';
|
||||
|
||||
const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101';
|
||||
|
||||
async function mintTicket(jwt: string): Promise<string> {
|
||||
const res = await fetch(`${BASE}/api/v1/stream/ticket`, {
|
||||
method: 'POST',
|
||||
headers: { Authorization: `Bearer ${jwt}` },
|
||||
});
|
||||
if (res.status !== 200) throw new Error(`mint failed: ${res.status} ${await res.text()}`);
|
||||
return (await res.json()).ticket;
|
||||
}
|
||||
|
||||
/** Open the SSE stream with a ticket, return the HTTP status, and tear the stream down. */
|
||||
async function openStream(ticket: string): Promise<number> {
|
||||
const c = new AbortController();
|
||||
try {
|
||||
const res = await fetch(`${BASE}/api/v1/stream?ticket=${encodeURIComponent(ticket)}`, {
|
||||
signal: c.signal,
|
||||
});
|
||||
return res.status;
|
||||
} finally {
|
||||
c.abort();
|
||||
}
|
||||
}
|
||||
|
||||
test.describe('Adversarial — SSE ticket abuse', () => {
|
||||
test('minting a ticket requires authentication', async () => {
|
||||
const res = await fetch(`${BASE}/api/v1/stream/ticket`, { method: 'POST' });
|
||||
@@ -40,7 +19,7 @@ test.describe('Adversarial — SSE ticket abuse', () => {
|
||||
|
||||
test('a ticket is single-use: replay after first open is rejected', async ({ guest }) => {
|
||||
const g = await guest('SseReplay');
|
||||
const ticket = await mintTicket(g.jwt);
|
||||
const ticket = await mintSseTicket(g.jwt);
|
||||
|
||||
// First open consumes the ticket.
|
||||
expect(await openStream(ticket)).toBe(200);
|
||||
|
||||
Reference in New Issue
Block a user