lundi 4 février 2019

Software QA: Handling injection in search fields

I am still quite new as a Software QA, and I haven't been able to get a solid answer on this one.

Say there is a search field on a web-page, and the user inputs something between two Script tags, how should the search field react?

My understanding is that the page should simply sanitize this and return whatever it could find as normal. The page in question however, throws a 500 Internal Server Error in the Devtools.

I noted this as something to fix, and the developer mocked me for it, stating that it would obviously respond like that.

Could anyone clarify for me whether this is something worth fixing, or if I am overestimating its importance. I really want to improve at my job, and am definitely finding it hard to know when I'm being too picky with my testing.

Aucun commentaire:

Enregistrer un commentaire