Skip to content

test: add real CSP violation assertions (#107 remainder) - #110

Merged
Xore merged 1 commit into
mainfrom
csp-violation-assertions
Aug 9, 2026
Merged

Xore merged 1 commit into
mainfrom
csp-violation-assertions

Conversation

@Xore

@Xore Xore commented Aug 9, 2026

Copy link
Copy Markdown
Owner

PR #109 left this explicit gap: "only console-error/external-request checks exist today." Those catch a violation only incidentally, if one happens to also log to console during a normal run -- neither proves the policy is actually enforced nor verifies its exact value.

What

  • `trackPageHealth()` now registers a `securitypolicyviolation` listener via `addInitScript` on every page it's attached to, and `assertHealthy()` (now async) fails on any real violation. Every existing call site gets this for free, matching the helper's own stated design goal ("every spec below gets this for free without repeating the wiring").
  • New "Testing: WebAuthn/passkey ceremony, select-authenticator, RTL, zoom, forced-colors, and CSP coverage #107 CSP enforcement" describe block:
    • Asserts the login page's actual `Content-Security-Policy` header matches Keycloak's real deployed default (`frame-src 'self'; frame-ancestors 'self'; object-src 'none';` -- confirmed live against the deployed realm's account console, not guessed; this repo's realm fixture carries no `browserSecurityHeaders` override, so Keycloak's own default applies).
    • Drives a real `object-src` violation (same-origin ``, so a failure can only mean object-src, never externalRequests/CORS) to prove enforcement actually fires, not just that the header is present.

      Test plan

      • Both new CSP tests pass against the real disposable-Keycloak harness
      • Full desktop-tier suite run: 2 pre-existing screenshot-diff failures (TOTP QR baseline, 200%-zoom baseline) reproduce identically on the unmodified file too -- confirmed via `git stash` + re-run -- environment font-rendering, not a regression from this change
      • CI

PR #109 left this explicit gap: "only console-error/external-request
checks exist today." Those catch a violation only incidentally, if one
happens to also log to console during a normal run -- neither proves the
policy is actually enforced nor verifies its exact value.

- trackPageHealth() now registers a securitypolicyviolation listener via
  addInitScript on every page it's attached to, and assertHealthy() (now
  async) fails on any real violation. Every existing call site gets this
  for free, matching the helper's own stated design goal.
- New "#107 CSP enforcement" describe block: asserts the login page's
  actual Content-Security-Policy header matches Keycloak's real deployed
  default (frame-src 'self'; frame-ancestors 'self'; object-src 'none';
  confirmed live against auth.<domain>/realms/apiary/account/, not
  guessed -- this repo's realm fixture carries no browserSecurityHeaders
  override, so Keycloak's own default applies), and drives a real
  object-src violation (same-origin <object>, so a failure can only mean
  object-src, never externalRequests/CORS) to prove enforcement actually
  fires, not just that the header is present.

Verified against the real disposable-Keycloak harness: both new tests
pass; the 2 pre-existing screenshot-diff failures elsewhere in the suite
(TOTP QR baseline, 200%-zoom baseline) reproduce identically on the
unmodified file too -- environment font-rendering, not a regression from
this change.
@Xore
Xore merged commit ce83cf4 into main Aug 9, 2026
3 checks passed
@Xore
Xore deleted the csp-violation-assertions branch August 9, 2026 07:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant