5 ms·
A comment in source code. Not the discerning professional's preferred tool for guaranteeing security-critical behaviors to prevent "fire holes".
by sukilot 6y ago
A comment in source code. Not the discerning professional's preferred tool for guaranteeing security-critical behaviors to prevent "fire holes".
- setzer22 6y agoWhat should they do? Static analysis would be nice, but it's probably too complex to adopt in that kind of codebase. In the end, the only viable option is to forbid this behaviour, and document a rationale so nobody will enable it back again. Perhaps they could make this warning bigger, but other than that...
- jefftk 6y agoThey could have added a regression test, no? Give it an example with ?attach= and verify that no attachment is added.