Repository navigation
test(setup): hostile-client fixtures against the real setup server (#173) - #315
Merged
Merged
Conversation
Contributor
Mira PR WalkthroughThis PR adds a comprehensive security test suite that validates the setup server's defenses against hostile client attacks. The new test runs against a real server instance with a malicious media server payload, checking protections against cross-site requests, DNS rebinding, forged headers, framing, and script injection. 1 file reviewed
|
Contributor
|
/mira pause |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
rowkav09
force-pushed
the
test/setup-hostile-fixtures
branch
from
September 23, 2026 23:44
7fa54b2 to
a9d7f9f
Compare
rowkav09
force-pushed
the
test/setup-hostile-fixtures
branch
from
September 23, 2026 23:47
a9d7f9f to
5498b8d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
New
test/setup-hostile.test.js. It runs against the real server fromstartSetupApp, with a media server whose name and version are an XSS payload. It checks what a hostile client could try:Sec-Fetch-Site: cross-site) gets 403. A legacy browser with no fetch-metadata sendingtext/plaingets 415.localhost.evil.example, orOrigin: nullgets 403.Sec-Fetch-Site, guessed cookie) get 403 without this run's session.X-Frame-Options: DENY,frame-ancestors 'none',script-src 'self'with no unsafe-inline/eval or remote hosts, and no inline<script>in the page.nosniff, and the page script has no HTML sinks (innerHTML,insertAdjacentHTML,document.write,eval,new Function). Provider text only goes throughtextContent.Why
This is the last checklist item on #173 ("hostile fixtures for DNS rebinding-style Host headers, cross-site forms/fetch, framing and injected provider text"). The other items are done:
The fixtures run at the HTTP level (what a browser would send), not in a headless browser. Keeping CI browser-free is deliberate.
Checks
Issue
Closes #173