PASS remote and imported client IDs, preview numbers and names remain text
PASS invoice dates, filter option IDs and action IDs remain text
PASS shift dates, times and action IDs remain text
PASS payment method IDs and labels remain text
PASS dangerous payment links and non-image data URLs never render
PASS valid payment links and uploaded logo formats are retained safely
PASS malicious ID is passed intact to the intended callback, never evaluated
PASS untrusted endpoint is rejected before any token can leave the browser
PASS legitimate Apps Script requests preserve protocol and keep token out of URL
PASS CSP forbids inline code, object embedding and unauthorized connections
PASS all rendered action names resolve to a registered callback
11 security tests passed. No production records or backend were accessed.
