# PRODUCT-3535 — manual video evidence

Acceptance for PRODUCT-3535 is **screen recordings**, not automated tests in the repo. Record short clips that show the behavior clearly; link them from the PR and Jira.

## Release lines

| Line | Example | Distribution |
|------|---------|--------------|
| **1.3.x** | `1.3.13` (patched) / `1.3.12` (vulnerable) | WordPress.org auto-update |
| **2.0.x** | `2.0.8+` (patched) / `2.0.7` (vulnerable) | Manual deploy |

## GREEN video (patched build — required for this PR)

Use a **real WordPress site in the browser** with the CourseStorm plugin installed (local, staging, or playground). **WP-CLI-only recordings are not sufficient.**

Show **1.3.13** (or your patched 1.3.x build):

1. **Plugins** — wp-admin → Plugins: CourseStorm **1.3.13** active.
2. **Administrator** — Log in as an admin → **Settings → CourseStorm** (or **CourseStorm for WordPress**). Show the settings screen loads and a valid catalog subdomain is configured.
3. **Subscriber / authorization** — Log in as a **Subscriber**. Confirm they **cannot** manage CourseStorm settings (no access to the settings screen and/or `admin-ajax.php` actions return **403** / error when attempting `coursestorm_options_save` with an invalid nonce — e.g. via Network tab or a same-origin `fetch` in the console while logged in as Subscriber).
4. **Front-end embed** — View the public site (or **View Catalog**). In **View Page Source** or **Network**, show embed assets load from `https://{valid-label}.coursestorm.com/...` only (no attacker host).

Do not demonstrate live SSRF against external hosts. Invalid subdomain labels should be rejected in admin before save.

**Suggested filename:** `PRODUCT-3535-green-1.3.x-browser.mp4`

## RED video (vulnerable baseline — for comparison / Jira)

Record against **1.3.12** or **2.0.7** without the patch, showing the original issue (Subscriber or CSRF path changing settings, and/or unsafe URL construction). Not required on the implementation PR if already captured in PRODUCT-3535 / #286.

**Suggested filenames:** `PRODUCT-3535-red-1.3.x.mp4`, `PRODUCT-3535-red-2.0.x.mp4`

## Attach

Upload to the PR (or artifact storage) and paste the link in the PR description under **Manual verification (video)**.
