I5:FeatureTest-RP Sanitization of Claims Containing HTML Entities
From OSIS Open Source Identity Systems
{{#vardefine:page|{{#if:{{#var:page}}|{{#var:page}}|FeatureTest-RP Sanitization of Claims Containing HTML Entities}}}}{{#vardefine:nr|{{#if:{{#var:nr}}|{{#expr:{{#var:nr}}+1}}|1}}}}{{#vardefine:url|{{#replace:{{#var:page}}| |_}}}}{{#if:RP Sanitization of Claims Containing HTML Entities|{{#if:{{#var:DtArticleSortKey}}||}}}}{{#ifeq:{{#var:header}}|no||
{{#if:{{#var:refs}}|[[{{#var:page}}|no_ref's]]|[[Special:Call/DT Article show Refs,page={{#var:page}},refs=yes|ref's]]}}}} | {{#if:{{#var:DtArticleSortKey}}|({{#var:DtArticleSortKey}})}} list help [[Special:Call/DT Article copy,cat=FeatureTest,from={{#var:page}},namespace=I5|copy]] [[Special:Call/DT Articles list XML,type=FeatureTest,title={{#var:page}},namespace=I5|as XML]] edit |
{{#if:|Feature Test |Feature Test }} | RP Sanitization of Claims Containing HTML Entities |
Test Type | bgcolor={{{color}}}}}|Claim Processing |
Identifier | bgcolor={{{color}}}}}|FTR-irp-claimprocessing-1 |
Description | bgcolor={{{color}}}}}|Tests that an RP is not susceptible to script-based injection attacks |
Role tested | bgcolor={{{color}}}}}|Information Card Relying Party |
Known Successful Reference Solution(s) | bgcolor={{{color}}}}}|{{ #if: | [[I5:]]}}{{ #if: | [[I5:]]}} {{ #if: | }} {{ #if: | }} |
Success Criteria | bgcolor={{{color}}}}}|No popups are displayed |
Failure Criteria | bgcolor={{{color}}}}}|One or more popups are displayed |
Features Proven
{{#dpl:debug=1
|resultsheader=\n |noresultsheader= {|\n|bgcolor=#eeeeee|No matching Feature found.\n|}\n |category=Feature |namespace=I5 |linksto=I5:FeatureTest-RP Sanitization of Claims Containing HTML Entities |nottitlematch = Feature.edit |include={Feature}.viewfromtest |includematch=/FeatureTest-RP Sanitization of Claims Containing HTML Entities/s |table=class=sortable,-,Feature,feature_type,solution_role
}}
Instructions
Instructions
- Open the result page for the Relying Party solution for this particular featuretest.
- Download the | HTML Entities Test Card
- Install it in your selector
- Navigate to the Relying Party Site
- Invoke the Selector
- Select Select the HTML Entities Card
- Validate Relying Party response
- Set outcome:
- If the RP does not popup any windows saying "hacked", set outcome to Works
- If javascript alert windows pop up, set outcome to Failed
- If you saw specific issues, mark the outcome as "Issues" and outline the issues by commenting on the "Talk" tab of this page
- Add either four tilde ~~~~ signs or a text name into the "testedby" parameter
- Update the date tested, operating systems, and tested solutions parameters of the results page