Confirmed users
3,816
edits
No edit summary |
|||
Line 32: | Line 32: | ||
* {{done|Ensure that in a situation where preflight is forced to be true (due to update progress listeners) we still do that even though everything else about our REQ is simple XSS}} | * {{done|Ensure that in a situation where preflight is forced to be true (due to update progress listeners) we still do that even though everything else about our REQ is simple XSS}} | ||
* {{done|test error handling when we get a XSS REQ and get a header not in RESP header whitelist - ensure both looking for specific header and looking for all headers doesn't display the header}} | * {{done|test error handling when we get a XSS REQ and get a header not in RESP header whitelist - ensure both looking for specific header and looking for all headers doesn't display the header}} | ||
* attempt to fake the origin on the REQ | * {{done|attempt to fake the origin on the REQ}} | ||
* {{skip|redirects (see redirect cases below)}} | * {{skip|redirects (see redirect cases below)}} | ||
* Cannot get document.cookie of requested resource | * Cannot get document.cookie of requested resource |