3 ms·
I don't think you're getting the point of the article. It is talking about dereferencing the STATE and the VALUE portions of a RESTful API. Not what's the most
by gootik 12y ago
I don't think you're getting the point of the article. It is talking about dereferencing the STATE and the VALUE portions of a RESTful API. Not what's the most secure way of sending a credit card number over TCP/IP.
- deleted 12y ago[deleted]
- gootik 12y agoThat's a very good point and I understand that. But webhat's comment makes it seem like the whole article is invalid or the example is not correct. I definitely would not consider this as an 'obvious error' with the example. Maybe bad practice. Would you say the copy/paste issue is solved if the author just does a mass replace from 'http' to 'https' on his articel?
- webhat 12y agoI would say yes, I've also advised the author of this mistake and he declined to modify it. This is the less that friendly reply I got: > You missed the absence of Content-Length in some of my examples? If you're going to be on this internet, friend, you've got to step up your pedantry game. https://github.com/teddziuba/teddziuba.github.com/commit/fd4b26d8fd4accc4bda62982710833cf798262e6 https://github.com/teddziuba/teddziuba.github.com/commit/fd4...
- webhat 12y agoI got the point exactly, and the paragraph under the example states: > The obvious problem with this is that we’re given a reference to the product, and not the product itself. Which isn't the most obvious problem with this example. You might want to read: https://www.owasp.org/index.php/REST_Security_Cheat_Sheet https://www.owasp.org/index.php/REST_Security_Cheat_Sheet