Re: Simple Proposal for setting HTTP headers

On 2013-07-23 15:33, Brad Hill wrote:
> Again, WebAppSec is an outlier, though not the only one.  I never
> expect or tests to work 100% from a mass-deployed local server as we
> depend on having multiple host names and, critically, having a trusted
> https endpoint available for our tests. 

Nevertheless it's important to figure out a strategy for running all 
tests in normal browser automation harnesses, regardless of whether they 
are "outliers" or not. Tests that aren't run are effectively useless and 
whilst security tests are disproportionately hard to run they are also 
disproportionately important.

Received on Tuesday, 23 July 2013 17:06:52 UTC