#!/usr/bin/env bash # LIVE-VM proof for the Phase A-tier-1 site-side rotation ENGINE (internal/browserrot), # inside the sandbox VM. FAKE credential only, against a throwaway in-process website — # nothing real is touched. # # What this proves is the deterministic browser-drive machinery that would run against a # real change-password page: # # * discover the change page via RFC 8615 /.well-known/change-password (real redirect) # * inject the OLD + a freshly-minted NEW password into the form over CDP, with NO # language model in the loop # * submit and read the site's SUCCESS marker # * VERIFY the new password authenticates by re-logging-in (hard rule 2), and confirm # the OLD password no longer works (the rotation is real, not a no-op) # # The engine is exercised by the CHROME_BIN-gated integration test # (TestIntegration_realBrowserRotation) driving a REAL headless Chromium. This is what # earns browserrot's LIVE-VM proof level for the ENGINE; a specific real-site selector # table stays UNPROVEN until it is run against that real site. # # It does NOT rotate any real account: only the user's own accounts, with explicit # per-credential authorization, may ever be driven against a real provider. set -euo pipefail export PATH=/usr/local/bin:$PATH # Locate a usable, NON-snap Chromium (snap chromium fights CDP + can't read /tmp). find_chrome() { for c in \ "${CHROME_BIN:-}" \ "$HOME"/.cache/ms-playwright/chromium-*/chrome-linux64/chrome \ "$HOME"/.cache/ms-playwright/chromium-*/chrome-linux/chrome \ /usr/bin/google-chrome /usr/bin/chromium /opt/google/chrome/chrome ; do [ -n "$c" ] && [ -x "$c" ] && { echo "$c"; return 0; } done return 1 } CHROME_BIN="$(find_chrome || true)" if [ -z "${CHROME_BIN:-}" ]; then echo "FAIL: no usable Chromium found. Install Chrome-for-Testing / google-chrome, or" echo " set CHROME_BIN to a chromium executable (a Playwright-managed one is ideal)." echo " hint: npx playwright install chromium" exit 1 fi echo "== using Chromium: $CHROME_BIN" "$CHROME_BIN" --version 2>/dev/null | sed 's/^/ /' || true # Run from the repo root (the dir containing go.mod). cd "$(git -C "$(dirname "$0")" rev-parse --show-toplevel 2>/dev/null || echo "$(dirname "$0")/..")" echo "== running the LIVE-VM browser-rotation proof ==" CHROME_BIN="$CHROME_BIN" go test -run TestIntegration_realBrowserRotation -v ./internal/browserrot/ echo echo "LIVE-VM BROWSER-ROTATION ENGINE PROOF PASSED"