{"content":"<section class=\"cache-poisoning-response\"><h3>Filtered Cache Response</h3><p><strong>Current Banner:</strong> Welcome to the shared cache demo</p><p>Obvious <code>&lt;script&gt;</code> tags are stripped, but the cache key remains route-only.</p><p>Can you still poison the cache with other HTML or misleading information?</p></section>","isValid":true}