Testing the Commercial SaaS Web Application
A complex Software as a Service (SaaS) system is adopted for the further case studies. We omit the system name for anonymous review reasons.
A complex Software as a Service (SaaS) system is adopted for the further case studies. We omit the system name for anonymous review reasons.
The above code segment shows a discovered failure, where gray lines are newly added fixing solutions. The elements (i.e., “kg-container”) is asynchronously rendered, which will be a null pointer before finishing rendering. Therefore, a failure will be triggered once accessing such a null pointer (Line 3). This finding also suggests that developers should pay attention when using asynchronous techniques in web applications.
The above code segment shows a module loading failure that results in a security defect. Specifically, when WebExplor operates on the “online-editor” in the browser, the server tries to load a non-existent module “brace/mode/c cpp” by traversing all folders (Line 3). Consequently, the server exposes all folders and folder structure to the client, which could be exploited by malicious attackers, and results in security problems. The “online-editor” is difficult to reach but WebExplor discovered it by adopting an effective exploration.
The above segment demonstrates a failure caused by invalid input values. Without validation before submitting a form to the server side will result in the failure. This failure is discovered by WebExplor, confirmed and fixed (line 2) by the developer.
The above codes show a dead looping (jumping) failure due to lacking of self-jumping checking. This failure casues a infinite url jumping and eventually a crash of the client. WebExplor spotted this failure via online testing, which is confirmed and fixed (line 2).