Add isolated file-upload form variants for DLP E2E testing
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 72/100
Hướng nghiên cứu
Start at the advanced-fields page and inspect the consuming apps/webext-e2e activity/file-upload DLP specs and their page-object selectors. Add isolated, stable file-upload form fixtures for the requested submit and destination cases, with a harmless same-origin endpoint, then verify the E2E specs can target them without serializing the existing catch-all form.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Context
The PixieBrix browser-extension file-upload DLP enforcer (activity Phase 5) gates uploads at the <form> submit vector and resolves the upload destination from the form's action — so apps/webext-e2e needs a faithful multipart form to drive it.
Today the advanced-fields page only has a file input nested inside the big catch-all <form class="input">, which has no action, no enctype, and no method. That's enough for the metadata-block-at-change test, but not for faithful submit/destination testing:
- The destination resolves to the page URL only (can't exercise destination-scoped rules).
- Submitting the shared catch-all form drags in every other field and does a real GET navigation.
A temporary E2E is landing against the catch-all form (using a synthetic submit event to avoid navigation), but we'd like a dedicated, isolated fixture to switch to.
Request
Add one or more isolated file-upload forms to the advanced-fields page (separate from <form class="input">), each with stable selectors (ids / aria-labels) and vendor-neutral example domains. Prioritized:
Must-have
- Basic single-file multipart POST form —
<form action="/dlp-upload" method="post" enctype="multipart/form-data">with a labeled<input type="file">+ a submit<button>. A same-originaction(a route that just returns204) so an allowed upload doesn't error the page (tests will also route-intercept it).
Nice-to-have (each exercises a specific enforcer branch)
- Cross-origin
action— same form butaction=\"https://uploads.example.com/files\", to test destination-scopedurlPatternrules (the enforcer judges origin + path). -
formactionoverride — a form with oneactionplus a submit<button formaction=\"https://uploads.example.com/other\">; the enforcer prefers the submitter'sformactionas the destination. -
form=-associated input outside the form —<input type=\"file\" form=\"<form-id>\">living outside the<form>subtree; the enforcer readsform.elementsto catch these. - Multiple-file input —
<input type=\"file\" multiple>for multi-file uploads. - Drag-and-drop dropzone — a labeled dropzone that accepts dropped files, for the
drop/pasteinterception vectors (a later follow-up).
Constraints
- Keep each form isolated from the existing catch-all
<form class="input">so submitting it doesn't serialize unrelated fields. - Stable, documented selectors (ids or
aria-labels) — the E2E page object targets these. - Use neutral
example.comdomains for cross-origin actions. - The endpoint(s) can be a trivial
204(Vercel serverless or a static handler) — no real storage needed.
Consumed by the pixiebrix-source apps/webext-e2e activity/file-upload DLP specs.
- Ngôn ngữ chính
- HTML
- Star
- 3
- Fork
- 1
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue tương tự
-
pending triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
nuxt/test-utils#1842 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 86/100
FinanceFlash/unvibecode#206 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
Maintainer thường phản hồi trong vòng 1 ngày
-
agent/scanner hive/hosted-available-lke648397-260827-5n31 quality testing
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
stryker-mutator/stryker-net#3892 ·
Maintainer thường phản hồi trong vòng 1 ngày