# Security Testing Guide
## Overview
This document outlines the security testing methodology and test cases for ActivityPub implementations.
## Security Test Categories
### 1. Cross-Site Scripting (XSS)
**Objective**: Identify if user-supplied content is properly sanitized before display.
**Test Cases**:
- Script tag injection: ``
- Event handler injection: `
`
- JavaScript protocol: `javascript:alert('XSS')`
- SVG-based XSS: `