Merge test/stored-xss-sse-abuse: stored-XSS + SSE-ticket abuse coverage

Add stored-XSS coverage for captions and comments (inert-render assertions) and
a new SSE-ticket-abuse spec (auth-required mint, single-use replay rejection,
garbage-ticket rejection).
This commit is contained in:
fabi
2026-07-01 07:34:56 +02:00
2 changed files with 61 additions and 0 deletions

View File

@@ -0,0 +1,61 @@
/**
* Phase 2 adversarial — SSE ticket capability abuse.
*
* The stream endpoint authenticates via short-lived, single-use tickets minted at
* POST /api/v1/stream/ticket (never the raw JWT in the URL). These tests pin the
* security properties of that flow: minting requires auth, and a ticket is consumed
* on first use so it cannot be replayed.
*/
import { test, expect } from '../../fixtures/test';
const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101';
async function mintTicket(jwt: string): Promise<string> {
const res = await fetch(`${BASE}/api/v1/stream/ticket`, {
method: 'POST',
headers: { Authorization: `Bearer ${jwt}` },
});
if (res.status !== 200) throw new Error(`mint failed: ${res.status} ${await res.text()}`);
return (await res.json()).ticket;
}
/** Open the SSE stream with a ticket, return the HTTP status, and tear the stream down. */
async function openStream(ticket: string): Promise<number> {
const c = new AbortController();
try {
const res = await fetch(`${BASE}/api/v1/stream?ticket=${encodeURIComponent(ticket)}`, {
signal: c.signal,
});
return res.status;
} finally {
c.abort();
}
}
test.describe('Adversarial — SSE ticket abuse', () => {
test('minting a ticket requires authentication', async () => {
const res = await fetch(`${BASE}/api/v1/stream/ticket`, { method: 'POST' });
expect(res.status).toBe(401);
});
test('a ticket is single-use: replay after first open is rejected', async ({ guest }) => {
const g = await guest('SseReplay');
const ticket = await mintTicket(g.jwt);
// First open consumes the ticket.
expect(await openStream(ticket)).toBe(200);
// Replaying the exact same ticket must fail — it was consumed, so `consume` returns
// None → 401. A 200 here would mean tickets are reusable (capability replay).
expect(await openStream(ticket)).toBe(401);
});
test('an unminted / garbage ticket is rejected', async () => {
// 24-byte-shaped hex string that was never issued.
const bogus = 'deadbeef'.repeat(6);
expect(await openStream(bogus)).toBe(401);
});
// Note: the replay test's first open (→ 200) already proves a freshly-minted ticket
// works, so there is no separate "fresh ticket" sanity test — a second successful open
// would just add ~30s (SSE headers flush on the keep-alive tick through Caddy).
});