From 20125fb71362ea8e2e87d4c35b2d85e83ea2f53b Mon Sep 17 00:00:00 2001 From: fabi Date: Wed, 1 Jul 2026 07:27:22 +0200 Subject: [PATCH] test(e2e): pin security assertions + real cross-user IDOR coverage MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Turn "accept-both-outcomes" documentation tests — which pass whether the app is secure or vulnerable — into assertions that pin the secure behavior, and replace fake-UUID authz tests that 404'd before ever reaching the ownership guard with real cross-user resources. file-upload-attacks: - SVG-with-