SnapOtter
3b181dd1ac
test: expand test coverage across unit, integration, e2e, and e2e-docker suites
...
Add ~210 new tests filling gaps identified by a comprehensive 14-agent
coverage audit. Unit+integration tests go from 9,388 to 9,484 (all passing).
Unit tests (+36):
- AI bridge: OOM fallback path, custom tier option
- Web lib: api-errors, format date/datetime, tool-i18n coverage
Integration tests (+19):
- Format matrix: ai-canvas-expand and find-duplicates added to cross-format matrix
- Adversarial: SVG XXE attacks, SQL injection in settings, request body size
limits, race conditions with identical filenames
E2E Docker (+3):
- ai-canvas-expand tool coverage with HEIC input and edge cases
E2E GUI (~150+):
- Navigation: login rate limiting, ai-canvas-expand in parameterized list
- Responsive: dropzone visibility, text readability, dialog bounds at all viewports
- Keyboard: shortcuts verified from automate, files, tool, and fullscreen pages
- Tool UI: undo/state-reset for 16 tools, crop canvas drag handles, rotate/border
live preview, linked aspect-ratio inputs for resize
- Batch: per-image undo isolation, batch compress/convert/rotate (not just resize)
- Pipeline: tool palette search, step collapse/expand visibility
- Settings: audit log entry verification, system settings persistence, teams CRUD,
role permission toggling
- RBAC: user/editor 403 on roles/teams endpoints, privilege escalation prevention,
cross-role tab parity documented as intentional
- Accessibility: skip-to-content link (WCAG 2.4.1), comprehensive color contrast
for all headings/body/buttons in both themes with DOM-walking background detection
- Resilience: auth expiry 401 redirect, rate limit 429 handling
- Performance: JS heap memory stability for tool navigation, dialog cycling,
upload/clear cycles, rapid page navigation
2026-05-15 21:35:02 +08:00
SnapOtter
ac8c585beb
fix: percent-encode X-File-Results header to support non-ASCII filenames
...
The X-File-Results header contained raw JSON with non-ASCII characters
from filenames (Chinese, Japanese, etc.), violating RFC 7230. Node.js
threw ERR_INVALID_CHAR on writeHead(). Fixed by wrapping the JSON in
encodeURIComponent() on the backend and decodeURIComponent() on the
frontend, ensuring only ASCII goes into the header while preserving
the original filenames after decoding.
Closes #133
2026-05-12 23:19:20 +08:00
SnapOtter
41455f98bd
test: add path traversal, null-byte, unicode, and concurrent request tests
...
New adversarial-security.test.ts covering 28 security-focused test cases:
- Path traversal attacks (7): Unix, Windows-style, URL-encoded, double-encoded, embedded
- Null byte injection (4): before extension, embedded, null-only, combined with traversal
- Extreme filename lengths (5): 1000-char, 5000-char, special-char-only, spaces, repeated dots
- Unicode filenames (8): Arabic RTL, Korean, Devanagari, complex emoji, RTLO char, ZWJ, tabs
- Concurrent request racing (4): 10 simultaneous with integrity check, batch+single isolation,
10 across 5 tools, adversarial+valid mixed
- Server stability (1): post-barrage health verification
No real vulnerabilities found -- sanitizeFilename() in lib/filename.ts properly
handles all tested attack vectors via basename(), dot-dot stripping, and null
byte removal.
2026-05-01 02:29:20 +08:00