{
  "schema": "starbound.lab-report.v1",
  "id": "lab-day1-fe-poc-2026-10-06",
  "title": "Starbound Lab — Day-1 dual-lane FE POC (DOM XSS + Clickjacking)",
  "published_at": "2026-10-06T14:41:19-04:00",
  "lab_zone": "starboundlab.com",
  "status": "pass",
  "summary": "Day-1 dual-lane FE POC verified: Juice DOM XSS (CWE-79 / OWASP A03) via promo.js→#promo-out innerHTML; Coffee clickjacking (CWE-1021 / OWASP A05) with frame-ancestors * + XFO ALLOWALL. Both intentional lab sinks reproducible. Apex still DENY. Prod untouched.",
  "score": {
    "passed": 8,
    "partial": 0,
    "skipped": 0,
    "failed": 0,
    "total": 8
  },
  "targets": [
    "https://starboundlab.com/",
    "https://starboundlab.com/juice/",
    "https://starboundlab.com/juice/promo.js",
    "https://starboundlab.com/juice/?promo=%3Cimg%20src=x%20onerror=alert('starbound-lab-xss')%3E",
    "https://starboundlab.com/juice/?promo=%3Cb%3ELAB%3C%2Fb%3E",
    "https://starboundlab.com/juice/?q=%3Csvg%20onload=alert(document.domain)%3E",
    "https://starboundlab.com/coffee/",
    "https://starboundlab.com/demo/clickjack",
    "https://starboundlab.com/coffee/clickjack.html",
    "https://starboundlab.com/coffee/clickjack",
    "https://starboundlab.com/coffee/loyalty"
  ],
  "checks": [
    {
      "id": "juice_sink_asset",
      "name": "Juice promo.js DOM XSS sink",
      "url": "https://starboundlab.com/juice/promo.js",
      "result": "pass",
      "http_status": 200,
      "detail": "promo.js present; reads promo then q; writes to #promo-out via out.innerHTML = \"Promo: \" + raw; INTENTIONAL SINK comment present"
    },
    {
      "id": "juice_csp_relax",
      "name": "Juice path CSP relax (XSS-enabling)",
      "url": "https://starboundlab.com/juice/",
      "result": "pass",
      "http_status": 200,
      "detail": "CSP script-src 'self' 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'none'; X-Frame-Options DENY (expected /juice/*)"
    },
    {
      "id": "juice_xss_reflect_html",
      "name": "Juice XSS reflect surface + PoC URLs",
      "url": "https://starboundlab.com/juice/?promo=%3Cb%3ELAB%3C%2Fb%3E",
      "result": "pass",
      "http_status": 200,
      "detail": "#promo-out present; promo.js wired; exec PoC + safe reflect + ?q= alias all HTTP 200. Reflection is client-side (curl cannot exec JS); sink confirmed via asset source"
    },
    {
      "id": "coffee_framable_headers",
      "name": "Coffee framable headers",
      "url": "https://starboundlab.com/coffee/",
      "result": "pass",
      "http_status": 200,
      "detail": "CSP frame-ancestors *; X-Frame-Options ALLOWALL (intentional framable lane)"
    },
    {
      "id": "coffee_framer_page",
      "name": "Coffee alt clickjack framer",
      "url": "https://starboundlab.com/coffee/clickjack",
      "result": "pass",
      "http_status": 200,
      "detail": "/coffee/clickjack.html 308→/coffee/clickjack; iframe src=\"./\" ; decoy over Claim free espresso"
    },
    {
      "id": "coffee_loyalty_bait",
      "name": "Coffee loyalty bait control",
      "url": "https://starboundlab.com/coffee/loyalty",
      "result": "pass",
      "http_status": 200,
      "detail": "Claim free espresso button (#loyalty-claim); framable headers (frame-ancestors *; XFO ALLOWALL)"
    },
    {
      "id": "apex_negative_control_headers",
      "name": "Apex negative control (still DENY)",
      "url": "https://starboundlab.com/",
      "result": "pass",
      "http_status": 200,
      "detail": "CSP frame-ancestors 'none'; X-Frame-Options DENY — apex not framable (negative control)"
    },
    {
      "id": "demo_clickjack",
      "name": "Primary demo clickjack framer",
      "url": "https://starboundlab.com/demo/clickjack",
      "result": "pass",
      "http_status": 200,
      "detail": "iframe src=\"/coffee/\"; decoy chrome over Claim free espresso; opacity:.55 teaching aid; pointer-events:none on decoy"
    }
  ],
  "findings": [
    {
      "id": "finding-day1-juice-dom-xss",
      "severity": "high",
      "title": "Juice lane — intentional DOM XSS via promo/q → innerHTML",
      "cwe": "CWE-79",
      "owasp": "A03:2021 Injection",
      "cvss_style": "AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (lab estimate ~6.1 Medium-High; treated High for demo impact)",
      "poc_url": "https://starboundlab.com/juice/?promo=%3Cimg%20src=x%20onerror=alert('starbound-lab-xss')%3E",
      "evidence": "curl -s https://starboundlab.com/juice/promo.js shows out.innerHTML = \"Promo: \" + raw after reading promo then q; #promo-out in juice/index.html; /juice/* CSP allows 'unsafe-inline'/'unsafe-eval' so classic onerror PoCs execute in-browser",
      "ti_note": "ClickFix-adjacent / promo-tampering narrative: attacker crafts a shareable promo URL; victim opens lab juice lane; payload executes in page origin. Maps to Magecart-style DOM injection and socially engineered \"promo code\" lures.",
      "detail": "Intentional Day-1 FE sink on owned lab asset. FE-only; no backend. Alias ?q= also sinks. Safe reflect PoC uses <b>LAB</b>."
    },
    {
      "id": "finding-day1-coffee-clickjacking",
      "severity": "medium",
      "title": "Coffee lane — intentional clickjacking (framable + decoy framer)",
      "cwe": "CWE-1021",
      "owasp": "A05:2021 Security Misconfiguration",
      "cvss_style": "AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N (lab estimate ~4.3 Medium)",
      "poc_url": "https://starboundlab.com/demo/clickjack",
      "evidence": "curl -sI /coffee/ → frame-ancestors *; X-Frame-Options: ALLOWALL. Primary framer /demo/clickjack embeds iframe src=/coffee/ with decoy overlay \"Claim free espresso\". Alt framer /coffee/clickjack; bait /coffee/loyalty.",
      "ti_note": "UI redress: attacker hosts a decoy loyalty reward page that invisibly frames the real Coffee claim control so a single click redeems/claims on the victim's session context.",
      "detail": "Intentional Day-1 FE framing weaken on /coffee/* only. Apex remains frame-ancestors 'none' + DENY (negative control verified)."
    },
    {
      "id": "info-xfo-allowall",
      "severity": "info",
      "title": "X-Frame-Options: ALLOWALL is nonstandard",
      "detail": "Coffee lane emits X-Frame-Options: ALLOWALL. This token is not in the XFO spec (DENY / SAMEORIGIN only). Modern browsers key off CSP frame-ancestors *; ALLOWALL is a teaching marker that the legacy header was deliberately neutralized. Prefer omitting XFO entirely when frame-ancestors governs, or document ALLOWALL as lab-only sentinel."
    },
    {
      "id": "info-demo-clickjack-duplicate-headers",
      "severity": "info",
      "title": "Option B — duplicate CSP/XFO on /demo/clickjack",
      "detail": "curl -sI https://starboundlab.com/demo/clickjack returns two Content-Security-Policy and two X-Frame-Options: DENY lines (path override + inherited /*). Both sets keep frame-ancestors 'none' / DENY so framer itself is not framable. Caveat for Vega/_headers hygiene: duplicate emission is harmless here but worth cleaning for clarity."
    },
    {
      "id": "info-coffee-clickjack-html-redirect",
      "severity": "info",
      "title": "/coffee/clickjack.html 308 → /coffee/clickjack",
      "detail": "Alt framer .html URL permanently redirects to extensionless /coffee/clickjack (HTTP 308 then 200). Document both; prefer canonical /coffee/clickjack and primary /demo/clickjack."
    }
  ],
  "links": {
    "hub": "https://starboundlab.com/",
    "juice": "https://starboundlab.com/juice/",
    "coffee": "https://starboundlab.com/coffee/",
    "demo_clickjack": "https://starboundlab.com/demo/clickjack",
    "juice_poc_exec": "https://starboundlab.com/juice/?promo=%3Cimg%20src=x%20onerror=alert('starbound-lab-xss')%3E",
    "juice_poc_safe": "https://starboundlab.com/juice/?promo=%3Cb%3ELAB%3C%2Fb%3E",
    "coffee_loyalty": "https://starboundlab.com/coffee/loyalty",
    "report_md": "/test-lab/reports/lab-day1-fe-poc-2026-10-06.md",
    "report_json": "/test-lab/reports/lab-day1-fe-poc-2026-10-06.json",
    "latest_json": "/test-lab/data/latest.json",
    "ir_juice": "/test-lab/reports/ir/day1-juice-dom-xss-ir.md",
    "ir_coffee": "/test-lab/reports/ir/day1-coffee-clickjacking-ir.md",
    "remediation_juice": "/test-lab/reports/remediation/day1-juice-dom-xss.md",
    "remediation_coffee": "/test-lab/reports/remediation/day1-coffee-clickjacking.md"
  },
  "brand": {
    "lab_only": true,
    "not_production": true
  },
  "owners": {
    "dns_tokens": "Orion",
    "content_deploy": "Vega",
    "devops_offsec": "Ragnar"
  }
}
