Web testing quickstart · Example directory
This repository is an intentionally vulnerable test fixture. Use synthetic data in a controlled environment; its behavior is not a production banking implementation.
A deliberately vulnerable banking application for demonstrating QualityMax testing capabilities.
DO NOT deploy this in production. This app contains intentional security vulnerabilities for testing purposes.
git clone https://github.com/Quality-Max/qualitymax-demo-bank.git
cd qualitymax-demo-bank
node server.jsThe app supports predictable live-demo states through DEMO_MODE:
DEMO_MODE=clean npm start # Stable happy-path app
DEMO_MODE=buggy npm start # Negative transfer bug enabled
DEMO_MODE=selector-change npm start # Clean behavior, changed transfer selectorUse npm test to verify the modes locally.
See DEMO_SETUP.md for the recommended Vercel deployments and paste-ready qmax-code demo prompts.
| Username | Password | Role |
|---|---|---|
| demo | demo123 | user |
| admin | admin | admin |
| jane | jane456 | user |
| Feature | What QualityMax Finds |
|---|---|
| Import REQUIREMENTS.md | Generates test cases from user stories |
| AI Crawl | Discovers all pages, forms, navigation flows |
| Gap Analysis | Missing error handling, edge cases, smoke tests |
| Security Scan | XSS, IDOR, CSRF, broken access control, mass assignment |
| k6 Load Test | API performance under load (/api/login, /api/transfer, /api/transactions) |
This app is designed for security testing demos. Vulnerabilities include:
- XSS: Search query reflected without sanitization
- IDOR: Any user can access any account via
/api/accounts/:id - CSRF: No CSRF tokens on any forms
- Broken Access Control:
/api/admin/usersaccessible to all authenticated users - Mass Assignment: Profile update API accepts
rolefield - Session Issues: No expiry, missing Secure/SameSite cookie flags
- No Rate Limiting: Login endpoint allows unlimited attempts
- Information Disclosure: Admin endpoint exposes passwords
- Timing Attack: Different response times for valid vs invalid usernames
- Input Validation: Negative transfer amounts accepted
See API.md for the full API specification.
qualitymax-demo-bank/
server.js # Node.js server (zero dependencies)
views/
login.html # Login page
dashboard.html # Account overview
transfer.html # Money transfer form
transactions.html # Transaction history with search
settings.html # Profile settings
docs.html # API documentation page
static/
style.css # Styles
REQUIREMENTS.md # User stories (import into QualityMax)
API.md # API spec (for k6 test generation)
SMOKE_TESTS.md # Incomplete smoke checklist (gap analysis bait)
MIT