Close two malicious-input gaps flagged in the suite review: XSS was only fuzzed through display_name, and the SSE ticket flow had no security assertions. xss-injection: - Stored XSS in captions — upload with each XSS payload as the caption, mark it feed-visible, render /feed and assert window.__xssFired stays false, no dialog fires, and no live `img[onerror]`/`<script>` element is produced (Svelte escaping renders it as inert text). A trailing CAPMARK gates the assertion on the caption actually having rendered, so it can't pass vacuously. - Stored XSS in comments — post the two render-executing payloads as a comment, open the lightbox (which loads comments) and assert the same inert-render props. sse-ticket-abuse (new): - Minting a ticket requires auth (POST /stream/ticket without Bearer → 401). - Single-use: after the first open consumes the ticket, replaying it → 401 (a 200 would be capability replay). The first open (→200) also proves a fresh ticket works. - An unminted/garbage ticket → 401. All verified green against the live backend. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
10 KiB
10 KiB