4 ms·
> The InvalidValuesInEnumsFieldsFuzzer will send invalid values in enum fields. It expects a validation error in return. The GitHub API does not seem to reject
by dtech 4y ago
> The InvalidValuesInEnumsFieldsFuzzer will send invalid values in enum fields. It expects a validation error in return. The GitHub API does not seem to reject invalid values, but rather convert them to a default value and respond successfully to the request. This is in contradiction with the OWASP recommendation around strong input validation and data type enforcing.
Doing this is incredibly good practice for compatibility, because otherwise you can never add or remove enum values because older clients will break on the unknown values. I also fail to see how it violates the recommendation, invalid data doesn't enter the system.
Imagine all webservers and browsers would need to be updated for every new HTTP header or status code is specified or web pages don't work anymore...
- ludovicianul 4y agoAs long as an API rejects invalid values if they are not part of an agreed list (but not enum), the same logic should apply for fields explicitly marked as enums. HTTP headers are not meant to be a limited set. As for the HTTP methods, it's a clear recommendation from OWASP to explicitly reject methods not supported by your API. It's like converting everything not known to POST...