5 ms·
Looks to me like they just insert the JSON body directly into Mongo without any sort of further validation: $m->tampon->queue->insert($post);
by sync 14y ago
Looks to me like they just insert the JSON body directly into Mongo without any sort of further validation:
$m->tampon->queue->insert($post);
- NathanKP 14y agoOoh yeah that isn't very good. They should really be using a JSON schema validation library to verify that someone isn't storing extra fields in the database, and that all the fields are of the right format and type.
- julien_c 14y agoYou're right. But the worst thing that can happen is someone POSTs large fake objects and tries to flood my server's hard drive. Which, given the max size of a POST's data will take quite some time :) The API only allows querying posts on the current user (with now user input) so there's no risk of "NoSQL injection": https://github.com/julien-c/Tampon/blob/master/api/posts.php https://github.com/julien-c/Tampon/blob/master/api/posts.php
- NathanKP 14y agoI see. I would still recommend JSON schema, though. It is great for debugging and ideal if you plan to open the API up to third party developers, because it makes it easy to ensure that all NoSQL data adheres to a proper schema, and it also provides meaningful error messages if a third party developer accidentally sends badly structured JSON to your service, or even if you accidentally send badly structured JSON to your service due to a front end bug. I use this JSON Schema validator with great success: http://packagist.org/packages/hasbridge/json-schema-validator http://packagist.org/packages/hasbridge/json-schema-validato...