PUZ-API-014

XSS attempt in puzzle data is escaped

Script tags in data don't execute

P0
automation
puzzle
api
security
xss
Test Steps
Steps to execute this test
  1. Load puzzle with malicious name
  2. Render in UI
Expected Result

Script is escaped, not executed. Shows as plain text.

Preconditions
  • Puzzle with script in name/description
Execution History
Recent test executions

This test has not been executed yet