OWASP / OWASP/ASVS

Clarification 1.2.1: How requirement apply to Single Page Applications (SPA) architectures

Open
#3,292 12 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

V1 (prev V5) Will be closed if no response/opposite arguments
Dominant language
HTML
Stars
3.6k
Forks
831
Avg merge
7h 55m
Merged PRs (30d)
4

Description

Rule: 1.2.1 - Verify that output encoding for an HTTP response, HTML document, or XML document is relevant for the context required...”

In most of the cases the Output encoding is primary responsibility of the client-side JavaScript framework, not the backend.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading requirement 1.2.1 in the raw Markdown under the ASVS 5.0 directory, then review the issue discussion about output encoding in SPA architectures. Done means reaching an agreed clarification of how the requirement applies to client-side JavaScript and backend responses and recording that clarification in the master text.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.