Skip to content

test(setup): hostile-client fixtures against the real setup server (#173) - #315

Merged
rowkav09 merged 1 commit into
mainfrom
test/setup-hostile-fixtures
Sep 23, 2026
Merged

rowkav09 merged 1 commit into
mainfrom
test/setup-hostile-fixtures

Conversation

@rowkav09

Copy link
Copy Markdown
Member

What changed

New test/setup-hostile.test.js. It runs against the real server from startSetupApp, with a media server whose name and version are an XSS payload. It checks what a hostile client could try:

  • Cross-site form post (urlencoded, foreign Origin, Sec-Fetch-Site: cross-site) gets 403. A legacy browser with no fetch-metadata sending text/plain gets 415.
  • Cross-site fetch with a JSON body from a foreign origin, a look-alike localhost.evil.example, or Origin: null gets 403.
  • DNS rebinding: reads and writes with a rebound Host get 421, even when the write carries the real session secret.
  • Forged browser headers from a local process (correct Origin and Sec-Fetch-Site, guessed cookie) get 403 without this run's session.
  • Framing and script: X-Frame-Options: DENY, frame-ancestors 'none', script-src 'self' with no unsafe-inline/eval or remote hosts, and no inline <script> in the page.
  • Injected provider text: discovery returns JSON with nosniff, and the page script has no HTML sinks (innerHTML, insertAdjacentHTML, document.write, eval, new Function). Provider text only goes through textContent.

Why

This is the last checklist item on #173 ("hostile fixtures for DNS rebinding-style Host headers, cross-site forms/fetch, framing and injected provider text"). The other items are done:

The fixtures run at the HTTP level (what a browser would send), not in a headless browser. Keeping CI browser-free is deliberate.

Checks

  • Tests pass locally (full suite green)
  • No secrets, tokens, server URLs, or personal media data are committed
  • Docs or tests were updated when behavior changed
  • The change is scoped to one roadmap issue

Issue

Closes #173

@mira-reviewer-rk

mira-reviewer-rk Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Mira PR Walkthrough

This PR adds a comprehensive security test suite that validates the setup server's defenses against hostile client attacks. The new test runs against a real server instance with a malicious media server payload, checking protections against cross-site requests, DNS rebinding, forged headers, framing, and script injection.

1 file reviewed


Comment @mira-reviewer-rk help to get the list of available commands and usage tips.

@github-actions

Copy link
Copy Markdown
Contributor

/mira pause

@github-actions github-actions Bot added the mira-paused Pause automatic Mira reviews on this pull request label Sep 23, 2026
@codecov

codecov Bot commented Sep 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

@rowkav09
rowkav09 force-pushed the test/setup-hostile-fixtures branch from 7fa54b2 to a9d7f9f Compare September 23, 2026 23:44
@rowkav09
rowkav09 force-pushed the test/setup-hostile-fixtures branch from a9d7f9f to 5498b8d Compare September 23, 2026 23:47
@rowkav09
rowkav09 merged commit c4967a8 into main Sep 23, 2026
11 checks passed
@rowkav09
rowkav09 deleted the test/setup-hostile-fixtures branch September 23, 2026 23:50
@github-project-automation github-project-automation Bot moved this from Backlog to Done in nowplaying Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

mira-paused Pause automatic Mira reviews on this pull request size:M

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

Harden localhost setup UI against cross-origin and injection attacks

1 participant