/** * Phase 2 adversarial — SSE ticket capability abuse. * * The stream endpoint authenticates via short-lived, single-use tickets minted at * POST /api/v1/stream/ticket (never the raw JWT in the URL). These tests pin the * security properties of that flow: minting requires auth, and a ticket is consumed * on first use so it cannot be replayed. */ import { test, expect } from '../../fixtures/test'; import { mintSseTicket, openStream } from '../../helpers/sse'; const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101'; test.describe('Adversarial — SSE ticket abuse', () => { test('minting a ticket requires authentication', async () => { const res = await fetch(`${BASE}/api/v1/stream/ticket`, { method: 'POST' }); expect(res.status).toBe(401); }); test('a ticket is single-use: replay after first open is rejected', async ({ guest }) => { const g = await guest('SseReplay'); const ticket = await mintSseTicket(g.jwt); // First open consumes the ticket. expect(await openStream(ticket)).toBe(200); // Replaying the exact same ticket must fail — it was consumed, so `consume` returns // None → 401. A 200 here would mean tickets are reusable (capability replay). expect(await openStream(ticket)).toBe(401); }); test('an unminted / garbage ticket is rejected', async () => { // 24-byte-shaped hex string that was never issued. const bogus = 'deadbeef'.repeat(6); expect(await openStream(bogus)).toBe(401); }); // Note: the replay test's first open (→ 200) already proves a freshly-minted ticket // works, so there is no separate "fresh ticket" sanity test — a second successful open // would just add ~30s (SSE headers flush on the keep-alive tick through Caddy). });