BeginnerInput Validation
Cross-Site Scripting Fundamentals
Understand stored, reflected and DOM sinks in a sandboxed app, then apply contextual output encoding.
Objectives
- Map untrusted input to render contexts
- Apply contextual encoding
- Deploy a restrictive Content-Security-Policy
- Verify the fix with regression checks
This lab runs in an isolated sandbox. Only use these techniques for authorized educational testing on systems you own or are explicitly permitted to test.