/** * Security fix F1: a plain host must not be able to demote a *peer host*. Before the * fix, `set_role` only blocked `target == admin`, so a host could demote another host * to guest and then ban / PIN-reset (→ account takeover via /recover) them, because the * ban/pin-reset peer guards key off the target's *current* role. This proves the * demotion itself is now blocked for non-admins, while admins and guest-management * still work. */ import { test, expect } from '../../fixtures/test'; const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101'; function patchRole(token: string, userId: string, role: string) { return fetch(`${BASE}/api/v1/host/users/${userId}/role`, { method: 'PATCH', headers: { Authorization: `Bearer ${token}`, 'Content-Type': 'application/json' }, body: JSON.stringify({ role }), }); } test.describe('AuthZ — host cannot demote a peer host (F1)', () => { test('host→host demotion is 403; admin may demote; host may still manage guests', async ({ host, guest, adminToken, api, }) => { // A second host (the victim) and an ordinary guest. const peer = await guest('PeerHost'); await api.setRole(adminToken, peer.userId, 'host'); const plain = await guest('PlainGuest'); // Attacker host tries to demote the peer host — must be refused. const attack = await patchRole(host.jwt, peer.userId, 'guest'); expect(attack.status, 'a host must not be able to demote a peer host').toBe(403); // An admin may still demote a host. const byAdmin = await patchRole(adminToken, peer.userId, 'guest'); expect(byAdmin.status).toBe(204); // A host may still manage guests (promote one to host). const promote = await patchRole(host.jwt, plain.userId, 'host'); expect(promote.status).toBe(204); }); });