Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Tiny Bug Child
Sep 11, 2004

Avoid Symmetry, Allow Complexity, Introduce Terror
picking up a thing from the closed thread

ErIog posted:

I got passed some code for security audit, and now the dev is arguing he doesn't need to validate this user input at all (for what should be an all-caps alphanumeric string) because the framework is making sure it's safe. It doesn't matter that this is being passed to things outside the dependency which don't check input at all. I should just sign off on it because, you see, this web framework said it was good input and that means you can drop it to the shell or just put it in a SQL query or do whatever with it.

I just want him to write like 10 lines of code to protect poo poo, but I guess that makes me an insane person.

that's 9 more lines than you should need but this dude is still completely in the right. you do not need to re-validate things the framework has validated for you. this is half the value of a web framework. if you insist on doing things that the framework has already done for you, why even bother using it

Adbot
ADBOT LOVES YOU

Tiny Bug Child
Sep 11, 2004

Avoid Symmetry, Allow Complexity, Introduce Terror

Rufus Ping posted:

what risk is it adding to other aws customers exactly

i assume it's that the agencies in question are perfectly willing to block all of aws or google or whoever if they don't comply, and their other customers who don't give a poo poo about signal don't want to get blocked

  • Locked thread