chore(e2e): add ESLint + Prettier; fix real findings; dedupe BASE
The Playwright suite had no linter and no formatter — only tsc. Add flat-config ESLint
(typescript-eslint, type-aware) and Prettier (2-space, matching the suite's style).
Rules keep the ones that catch real TEST bugs and drop the noise:
- no-floating-promises KEPT — an un-awaited request/assertion can let a test end before it runs,
passing vacuously. It caught one: the SSE reader loop in sse-listener is now explicitly `void`.
- no-unused-vars KEPT — caught three dead bindings (an unused adminToken fixture arg, an unused
`api` arg, an unused JPEG_MAGIC import), all removed.
- no-explicit-any OFF — all test code; `any` is the honest type for an untyped res.json() body or
a page.evaluate() return.
- no-empty-pattern OFF — Playwright's dependency-free fixtures are `async ({}, use) => {}`.
Refactor: `const BASE = process.env.E2E_FRONTEND_URL ?? '...'` was redeclared verbatim in 23
files — extracted to helpers/env.ts and imported, so a port/scheme change is one edit not a sweep.
Then `prettier --write`. Verified: eslint clean, tsc clean, prettier clean, desktop suite 210
passed / 1 skipped. (One mobile spec flaked once under retries:0 — a pre-existing cross-test
reflow-timing vector from the flakiness audit, not this change: the each-key edit is stable across
16 isolated runs and a clean full mobile re-run.)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -6,15 +6,16 @@
|
||||
*/
|
||||
import { test, expect } from '../../fixtures/test';
|
||||
import { seedUpload, seedComment, listComments, findFeedRow } from '../../helpers/seed';
|
||||
|
||||
const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101';
|
||||
import { BASE } from '../../helpers/env';
|
||||
|
||||
test.describe('Adversarial — deep authorization', () => {
|
||||
// IDOR: user B must not be able to delete user A's REAL comment. This exercises the
|
||||
// ownership guard (`comment.user_id != auth.user_id` → 403) — the previous version fired
|
||||
// at the all-zeros UUID, which 404s at the lookup BEFORE that guard runs, so it never
|
||||
// tested authorization at all.
|
||||
test('user B cannot delete user A\'s comment (real resource → 403, comment survives)', async ({ guest }) => {
|
||||
test("user B cannot delete user A's comment (real resource → 403, comment survives)", async ({
|
||||
guest,
|
||||
}) => {
|
||||
const a = await guest('CommentOwnerA');
|
||||
const b = await guest('AttackerB');
|
||||
|
||||
@@ -42,7 +43,7 @@ test.describe('Adversarial — deep authorization', () => {
|
||||
});
|
||||
|
||||
// IDOR: user B must not be able to delete user A's REAL upload.
|
||||
test('user B cannot delete user A\'s upload (403, upload survives)', async ({ guest, db }) => {
|
||||
test("user B cannot delete user A's upload (403, upload survives)", async ({ guest, db }) => {
|
||||
const a = await guest('UploadOwnerA');
|
||||
const b = await guest('AttackerB2');
|
||||
|
||||
@@ -60,7 +61,7 @@ test.describe('Adversarial — deep authorization', () => {
|
||||
});
|
||||
|
||||
// IDOR: user B must not be able to edit (re-caption / re-tag) user A's upload.
|
||||
test('user B cannot edit user A\'s upload caption (403, caption unchanged)', async ({ guest }) => {
|
||||
test("user B cannot edit user A's upload caption (403, caption unchanged)", async ({ guest }) => {
|
||||
const a = await guest('UploadOwnerA2');
|
||||
const b = await guest('AttackerB3');
|
||||
|
||||
@@ -75,7 +76,9 @@ test.describe('Adversarial — deep authorization', () => {
|
||||
expect(res.status).toBe(403);
|
||||
|
||||
// No state change: the caption A set is intact.
|
||||
const feedRes = await fetch(`${BASE}/api/v1/feed`, { headers: { Authorization: `Bearer ${a.jwt}` } });
|
||||
const feedRes = await fetch(`${BASE}/api/v1/feed`, {
|
||||
headers: { Authorization: `Bearer ${a.jwt}` },
|
||||
});
|
||||
const row = findFeedRow(await feedRes.json(), uploadId);
|
||||
expect(row?.caption).toBe('original caption');
|
||||
});
|
||||
@@ -115,7 +118,11 @@ test.describe('Adversarial — deep authorization', () => {
|
||||
expect(await listComments(host.jwt, uploadId)).toHaveLength(0);
|
||||
});
|
||||
|
||||
test('banned user can still read the feed (read-only access preserved)', async ({ api, host, guest }) => {
|
||||
test('banned user can still read the feed (read-only access preserved)', async ({
|
||||
api,
|
||||
host,
|
||||
guest,
|
||||
}) => {
|
||||
const target = await guest('BannedRead');
|
||||
await api.banUser(host.jwt, target.userId);
|
||||
|
||||
@@ -126,7 +133,11 @@ test.describe('Adversarial — deep authorization', () => {
|
||||
expect(res.status).toBe(200);
|
||||
});
|
||||
|
||||
test('host cannot delete another host\'s session via /api/v1/session', async ({ api, host, guest }) => {
|
||||
test("host cannot delete another host's session via /api/v1/session", async ({
|
||||
api,
|
||||
host,
|
||||
guest,
|
||||
}) => {
|
||||
const otherHost = await guest('OtherHost');
|
||||
// Promote so they have a host JWT to play with.
|
||||
await api.setRole(host.jwt, otherHost.userId, 'host');
|
||||
|
||||
Reference in New Issue
Block a user