mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-06 15:02:20 +02:00
fix(security): harden browser security boundaries
Reject unsafe metric ledger keys, keep email HTML inspection inert, and construct gallery thumbnails structurally. Add adversarial browser regressions for the remaining CodeQL security boundaries.
This commit is contained in:
@@ -15,3 +15,16 @@ def test_codeql_security_browser_contracts():
|
||||
"chat": True, "markdown": True, "svg": True,
|
||||
"menus": True, "admin": True, "bootstrap": True,
|
||||
}
|
||||
|
||||
|
||||
def test_pr6503_ledger_email_and_gallery_security_contracts():
|
||||
root = Path(__file__).resolve().parents[1]
|
||||
result = subprocess.run(
|
||||
["node", "tests/pr6503_security_browser.cjs"], cwd=root,
|
||||
capture_output=True, text=True, timeout=60,
|
||||
)
|
||||
assert result.returncode == 0, result.stdout + result.stderr
|
||||
assert json.loads(result.stdout) == {
|
||||
"ledger": True, "email": True, "gallery": True, "links": True, "skills": True,
|
||||
"sanitizer": True, "print": True,
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user