Turn "accept-both-outcomes" documentation tests — which pass whether the app is secure or vulnerable — into assertions that pin the secure behavior, and replace fake-UUID authz tests that 404'd before ever reaching the ownership guard with real cross-user resources. file-upload-attacks: - SVG-with-<script> → pin 400 (infer returns None for text → stored-XSS defense); was [201,400], which accepted the vulnerable outcome. - zero-byte → pin 400; path-traversal → pin 201 with UUID-derived storage and a no-path-echo check (both were [201,400]). - Fix the application/octet-stream rationale (no "application bypass" exists — the handler ignores the declared type and keys off magic bytes). authorization-deep (IDOR): - B deleting A's comment: seed a real upload+comment as A, assert 403, assert the comment survives, and assert the owner (A) still gets 204 — proving the 403 is about identity, not a broken route. (Was a DELETE on the all-zeros UUID → 404 before the user_id guard, so authorization was never exercised.) - Add B-deletes-A's-upload (403, countUploads unchanged) and B-edits-A's-caption (403, caption intact) — the find_by_id_and_event + ownership guards. export: pin the ZIP-download 404 (was [404,200] — a 200 is a data-exposure regression) and split into the two real branches: not-yet-ready, and ready-but-file-missing (new db.setExportZipReady helper). All 21 assertions verified green against the live secure backend. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
96 lines
3.4 KiB
TypeScript
96 lines
3.4 KiB
TypeScript
/**
|
|
* Direct PostgreSQL escape hatch for setting up states the public API doesn't
|
|
* expose — e.g. forcing a user into the locked-PIN state to assert the 429
|
|
* recovery path, or expiring sessions for chaos tests.
|
|
*
|
|
* Most tests should NOT use this: prefer `ApiClient` so the tests exercise
|
|
* the same code paths real users do. Reach for direct SQL only when the API
|
|
* can't get you where you need to go.
|
|
*/
|
|
import { Client } from 'pg';
|
|
|
|
const CONN = {
|
|
host: process.env.E2E_DB_HOST ?? 'localhost',
|
|
port: Number(process.env.E2E_DB_PORT ?? '55432'),
|
|
user: process.env.E2E_DB_USER ?? 'eventsnap_test',
|
|
password: process.env.E2E_DB_PASSWORD ?? 'eventsnap_test',
|
|
database: process.env.E2E_DB_NAME ?? 'eventsnap_test',
|
|
};
|
|
|
|
async function withClient<T>(fn: (c: Client) => Promise<T>): Promise<T> {
|
|
const client = new Client(CONN);
|
|
await client.connect();
|
|
try {
|
|
return await fn(client);
|
|
} finally {
|
|
await client.end();
|
|
}
|
|
}
|
|
|
|
export const db = {
|
|
async lockUserPin(userId: string, minutesFromNow = 15) {
|
|
await withClient((c) =>
|
|
c.query(
|
|
`UPDATE "user" SET pin_locked_until = NOW() + ($2 || ' minutes')::interval, failed_pin_attempts = 3 WHERE id = $1`,
|
|
[userId, String(minutesFromNow)]
|
|
)
|
|
);
|
|
},
|
|
|
|
async expireSession(userId: string) {
|
|
await withClient((c) =>
|
|
c.query(`UPDATE session SET expires_at = NOW() - interval '1 hour' WHERE user_id = $1`, [userId])
|
|
);
|
|
},
|
|
|
|
async setUploadCompressionStatus(uploadId: string, status: 'pending' | 'processing' | 'done' | 'failed') {
|
|
await withClient((c) =>
|
|
c.query(`UPDATE upload SET compression_status = $2 WHERE id = $1`, [uploadId, status])
|
|
);
|
|
},
|
|
|
|
async countUploadsForUser(userId: string): Promise<number> {
|
|
return withClient(async (c) => {
|
|
const r = await c.query<{ count: string }>(
|
|
`SELECT COUNT(*)::text AS count FROM upload WHERE user_id = $1 AND deleted_at IS NULL`,
|
|
[userId]
|
|
);
|
|
return Number(r.rows[0].count);
|
|
});
|
|
},
|
|
|
|
async setExportReleased(slug: string, released: boolean) {
|
|
await withClient((c) =>
|
|
c.query(`UPDATE event SET export_released_at = $2 WHERE slug = $1`, [
|
|
slug,
|
|
released ? new Date() : null,
|
|
])
|
|
);
|
|
},
|
|
|
|
/**
|
|
* Flip the `export_zip_ready` gate directly. The download handler serves bytes
|
|
* only when this boolean is true AND the file exists on disk, so setting it true
|
|
* without a file lets tests exercise the "ready but file missing" 404 branch.
|
|
*/
|
|
async setExportZipReady(slug: string, ready: boolean) {
|
|
await withClient((c) =>
|
|
c.query(`UPDATE event SET export_zip_ready = $2 WHERE slug = $1`, [slug, ready])
|
|
);
|
|
},
|
|
|
|
/** Insert a pre-baked export job row to skip the (slow) real compression path. */
|
|
async fakeExportJob(eventSlug: string, type: 'zip' | 'html', status: 'pending' | 'running' | 'done') {
|
|
await withClient(async (c) => {
|
|
const ev = await c.query<{ id: string }>(`SELECT id FROM event WHERE slug = $1`, [eventSlug]);
|
|
if (ev.rows.length === 0) throw new Error(`No event with slug ${eventSlug}`);
|
|
await c.query(
|
|
`INSERT INTO export_job (event_id, type, status, progress_pct, completed_at)
|
|
VALUES ($1, $2::export_type, $3::export_status, $4, $5)
|
|
ON CONFLICT (event_id, type) DO UPDATE SET status = EXCLUDED.status, progress_pct = EXCLUDED.progress_pct`,
|
|
[ev.rows[0].id, type, status, status === 'done' ? 100 : 0, status === 'done' ? new Date() : null]
|
|
);
|
|
});
|
|
},
|
|
};
|