Confirmed users
3,816
edits
No edit summary |
No edit summary |
||
Line 32: | Line 32: | ||
* test error handling when we get a XSS REQ and get a header not in RESP header whitelist - ensure both looking for specific header and looking for all headers doesn't display the header | * test error handling when we get a XSS REQ and get a header not in RESP header whitelist - ensure both looking for specific header and looking for all headers doesn't display the header | ||
* attempt to fake the origin on the REQ | * attempt to fake the origin on the REQ | ||
* skip redirects (see redirect cases below) | * {{skip|redirects (see redirect cases below)}} | ||
* Cannot get document.cookie of requested resource | * Cannot get document.cookie of requested resource | ||
* Ensure no trusted data ever exposed of the resource | * Ensure no trusted data ever exposed of the resource |