mirror of
https://github.com/elicpeter/nyx.git
synced 2026-06-15 20:05:13 +02:00
[pitboss] phase 02: M2 — Python end-to-end excellence with all hardening baked in
This commit is contained in:
parent
894f587b60
commit
0bf39047b9
50 changed files with 4167 additions and 170 deletions
12
tests/dynamic_fixtures/python/xss_negative.py
Normal file
12
tests/dynamic_fixtures/python/xss_negative.py
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
"""XSS — negative fixture.
|
||||
|
||||
Safe function: uses html.escape() before rendering.
|
||||
Expected verdict: NotConfirmed (script tag escaped to <script>).
|
||||
"""
|
||||
import html
|
||||
|
||||
|
||||
def render_comment(user_input):
|
||||
"""Safe: HTML-escapes user input before rendering."""
|
||||
safe = html.escape(user_input)
|
||||
print(f"<div class='comment'>{safe}</div>")
|
||||
Loading…
Add table
Add a link
Reference in a new issue