Can you please check the grading. The alert is not triggered because I did not allow the modal to pop up, but does that mean that the click is not redirected? I don't think so because allow scripts and allow forms was included in my solution. So everything in victim should be executed, but the victims alert will not be executed. I know that in this Case the alert is the only thing the button will do, but I misinterpreted that
- The button MUST NOT execute an alert
was mean that the victims alert should also be not executed... The auto graded capped my solution because the victims alert is not shown, but in the logic of clickjacking, that should be even better because the attacked user did not get this warning... Can you manually check this? Jan Matti Irmscher.