4 ms·
>> This could have been prevented on the server side by doing less strict input validation in compliance with Postel's Law. I feel nervous about making such a s
by sim7c00 1y ago
>> This could have been prevented on the server side by doing less strict input validation in compliance with Postel's Law. I feel nervous about making such a security-sensitive endpoint more liberal with the inputs it can accept, but it may be fine? I need to consult with a security expert.
if its possible to keep it strict, keep it strict. if another solution holds, even if it seems like a band aid, it will be better than relaxing input rules on something like this.
I am not specifically expert in these types of systems regarding their security, but this is the general case for such issues if you look at security from a general stance.
The trunc, i am not sure how expensive it is as an operation, but that seems like a good solution to me to sanitize the input. That way you can still 'detect' and reject invalid inputs (floats). handling floats is very different than integers (with things like NaN / inf etc.) so if you want to allow floats thats' a whole new area you need to test etc. rather than simply rejectig the invalid input.