Inert encoding and DOM-context matrix
Each case describes a fixed source token, a normalization step, and a serialized token.
The tokens contain identifiers only. They are never interpreted as markup, script, style, a URL, or an event handler. Unknown case values are rejected without reflection.
- html-text — entity-roundtripscript-element shape label; inert server-defined canary.
- quoted-attribute-text — quote-normalizationevent-handler shape label; inert server-defined canary.
- url-attribute-text — scheme-canonicalizationjavascript-url shape label; inert server-defined canary.
- inert-template-text — entity-roundtripscript-element shape label; inert server-defined canary.
- data-attribute-text — percent-decodeevent-handler shape label; inert server-defined canary.
- json-data-text — unicode-roundtripjavascript-url shape label; inert server-defined canary.
Measurement marker: ARN-BOUNDARY-XSS-CONTEXT-MATRIX