Follow-ups from the code review of the test-quality batches: - Consolidate duplicated helpers into e2e/helpers/: seed.ts (seedUpload, seedComment, listComments, findFeedRow) and sse.ts (mintSseTicket, openStream, trackStreamOpens). Refactor authorization-deep, xss-injection, like-comment, sse-ticket-abuse, ddos, sse-realtime, multi-tab, and SseListener to use them — the upload/comment/ticket-flow contracts now live in one place each instead of being re-inlined across 3–7 specs. - xss-injection display-name loop: it navigated to /feed (which renders uploader names, not the viewer's) so "nothing fired" passed vacuously — the payload was never rendered. Now navigate to /account (the actual sink) and add a render guard asserting the payload reached the DOM as escaped text before checking __xssFired. - sse-realtime reconnect: snapshot the stream-open count AFTER backgrounding, so the "new connection" assertion is attributable to the foreground event and can't be satisfied by a spurious native/error reconnect before the toggle. - recover-page: correct the comment (auto-submit is the onPinInput handler, not an $effect). 44 affected specs verified green. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
41 lines
1.7 KiB
TypeScript
41 lines
1.7 KiB
TypeScript
/**
|
|
* Phase 2 adversarial — SSE ticket capability abuse.
|
|
*
|
|
* The stream endpoint authenticates via short-lived, single-use tickets minted at
|
|
* POST /api/v1/stream/ticket (never the raw JWT in the URL). These tests pin the
|
|
* security properties of that flow: minting requires auth, and a ticket is consumed
|
|
* on first use so it cannot be replayed.
|
|
*/
|
|
import { test, expect } from '../../fixtures/test';
|
|
import { mintSseTicket, openStream } from '../../helpers/sse';
|
|
|
|
const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101';
|
|
|
|
test.describe('Adversarial — SSE ticket abuse', () => {
|
|
test('minting a ticket requires authentication', async () => {
|
|
const res = await fetch(`${BASE}/api/v1/stream/ticket`, { method: 'POST' });
|
|
expect(res.status).toBe(401);
|
|
});
|
|
|
|
test('a ticket is single-use: replay after first open is rejected', async ({ guest }) => {
|
|
const g = await guest('SseReplay');
|
|
const ticket = await mintSseTicket(g.jwt);
|
|
|
|
// First open consumes the ticket.
|
|
expect(await openStream(ticket)).toBe(200);
|
|
|
|
// Replaying the exact same ticket must fail — it was consumed, so `consume` returns
|
|
// None → 401. A 200 here would mean tickets are reusable (capability replay).
|
|
expect(await openStream(ticket)).toBe(401);
|
|
});
|
|
|
|
test('an unminted / garbage ticket is rejected', async () => {
|
|
// 24-byte-shaped hex string that was never issued.
|
|
const bogus = 'deadbeef'.repeat(6);
|
|
expect(await openStream(bogus)).toBe(401);
|
|
});
|
|
// Note: the replay test's first open (→ 200) already proves a freshly-minted ticket
|
|
// works, so there is no separate "fresh ticket" sanity test — a second successful open
|
|
// would just add ~30s (SSE headers flush on the keep-alive tick through Caddy).
|
|
});
|