Feature 9
Security test harness
Documented threats backed by automated tests.
Live 2,000+ Vitest cases across crypto, revoke, vouch, live control, scan, device shell, hosted tier
About this feature
Why it matters
Recruiters and security reviewers should see boundaries enforced in CI - not only in markdown threat models.
Design decisions
Shared crypto module for Worker + browser parity tests. Fake D1 layers for resolver handlers. Scan HTML regression tests for trust copy and live-control states.
Safety · privacy · security
Covers replay nonces, signature mismatch, vouch quotas, live-control expiry, verification display overrides. Adversarial review doc in repo for open questions.
Limits
No production penetration test report yet. Playwright E2E covers device shell, hosted tier, and merch paths; stranger create loop is runbook-driven.
Future directions
Fuzzing on canonicalization, operator abuse simulation fixtures, periodic test-count refresh on hub.