fix(security): address CodeQL findings in migration candidate

This commit is contained in:
CI Test
2026-10-05 20:48:12 +01:00
parent 4b140043bb
commit 059ac58cff
11 changed files with 351 additions and 18 deletions
+31
View File
@@ -67,6 +67,37 @@ def test_baseline_covers_every_inventory_entry():
assert set(baseline["variants"][name]) == variant_names
@_requires_browser
def test_capture_does_not_execute_script_markup_or_handlers(tmp_path):
"""Use the real capture subprocess: every script vector would turn green."""
attack = "document.getElementById('guard').style.color='rgb(0, 128, 0)'"
source = f'''<!doctype html><html><head><style>#guard {{ color: rgb(255, 0, 0); }}</style></head>
<body onload="{attack}"><div id="guard">Stable</div>
<script>{attack}</script >
<SCRIPT>{attack}</SCRIPT>
<script data-note=">">{attack}</script\t>
<script src="attack.js"></script>
<svg onload="{attack}"><script>{attack}</script></svg>
<img src=x onerror="{attack}">
<template><script>{attack}</script></template>
</body></html>'''
(tmp_path / "fixture.html").write_text(source)
(tmp_path / "attack.js").write_text(attack)
inventory = {
"properties": ["color"],
"variants": [snapshot.load_inventory()["variants"][0]],
"pages": [{"name": "fixture", "url": "/fixture.html",
"elements": [{"key": "guard", "selector": "#guard"}]}],
}
origin, shutdown = snapshot.serve_repository(tmp_path)
try:
captured = snapshot.capture(origin, inventory, measurement_delay_ms=100)
assert captured["missing"] == {}
assert captured["snapshot"]["fixture"][inventory["variants"][0]["name"]]["guard"]["color"] == "rgb(255, 0, 0)"
finally:
shutdown()
@_requires_browser
def test_computed_styles_match_the_committed_baseline():
captured = snapshot.capture(static_origin())