GSA / smartpay-website

SmartPay website
https://federalist-ab31a10d-375d-4040-9324-1ae94e8a36b9.sites.pages.cloud.gov/site/gsa/smartpay-website/
3 stars 0 forks source link

Code Scanning Alert: Incomplete URL substring sanitization #551

Open JennaySDavis opened 3 months ago

JennaySDavis commented 3 months ago

Sanitizing untrusted URLs is an important technique for preventing attacks such as request forgeries and malicious redirections. Usually, this is done by checking that the host of a URL is in a set of allowed hosts.

JennaySDavis commented 3 months ago

#551 Acceptance Criteria

Pass/Fail Description
Pass Smoke Testing of the Program Website

Comments/Additional Notes A link checker was completed on the application there were no broken links found

ADA Compliance (Automated scan via Chrome Lighthouse)

Criteria Score
Performance 99
Accessibility 100
Best Practices 100

Passed 06/05/2024 - JSD

LoraBradford commented 3 months ago

Moving to done, thank you!