How to test for DOM-based cross-site scripting