Security Tests

Every validation rule is verified with automated tests.

Test Categories

Our test suite covers all aspects of HTTP security validation.

Path Validation

15 Tests

URL path allowlist, traversal prevention, query string validation.

Details

HTTP Methods

8 Tests

Method allowlist per path, CORS preflight handling.

Details

Header Validation

12 Tests

Content-Type checking, header injection prevention, size limits.

Details

Form Validation

20 Tests

Field validation, type checking, length constraints, format validation.

Details

Injection Prevention

30 Tests

SQL injection, XSS, command injection, path traversal.

Details

Response Validation

18 Tests

Error sanitization, header cleanup, cookie security.

Details

Security Headers

10 Tests

CSP, HSTS, X-Frame-Options, X-Content-Type-Options injection.

Details

TLS/SSL

8 Tests

TLS version enforcement, cipher suite validation, certificate checks.

Details

Edge Cases

15 Tests

Unicode handling, encoding attacks, malformed requests.

Details

BSI IT-Grundschutz Mapping

APP.3.2.A11

TLS termination with configurable cipher suites and modern cryptographic standards.

APP.3.1.A21

Automatic injection of security headers (CSP, HSTS, X-Frame-Options).

APP.3.2.A12

Error sanitization removing stack traces, SQL errors, and internal IPs.

APP.3.1.A20

Form validation with type, format, and length checks.