4 ms·
Hell, I can forgive it in games -- it seems pretty easy to forget a detail that can accidentally give too much authority to a user in that space, especially whe
by skipants 5y ago
Hell, I can forgive it in games -- it seems pretty easy to forget a detail that can accidentally give too much authority to a user in that space, especially when you're trying to crunch your frame time.
What really surprises me is how how often I see this mistake in web development. "No, Bob, you should not increase the user's bank account based on that number passed in from the frontend React app."
- tshaddox 5y agoI'm not sure exactly what you mean. If it's a web API request from a web client that says "transfer $1,000 between account A and account B," then what choice do you have but to "trust" that number? Obviously you have to check whether the request is authenticated and is authorized to transfer between those accounts, and check if account A has $1,000, but what about the client origin of the request do you need to check?
- Tainnor 5y agoI mean since we're talking about banking: - Generate a transaction number and associate that number with the respective transaction details - Send this number to the customer's mobile phone with all those details, or other configured device - the transfer is only authorised if the customer has entered the transaction number That way, the customer is very likely to have verified the details of the transfer.
- skipants 5y ago> and check if account A has $1,000 It was a convoluted example for examples sake, but I'm pretty much referring to them missing this important check here.
- nend 5y agoThey're just saying to validate user input.