proposal: add requirement to verify that using a sanitization is an accepted solution for that data or flow
Nobody has claimed this yet.
- Dominant language
- HTML
- Stars
- 3.6k
- Forks
- 832
- Avg merge
- 7h 55m
- Merged PRs (30d)
- 4
Description
To make things related to the sanitization topic clearer, we need to be sure that sanitization as a defense is an acceptable option for the current data or process.
I think it would be good to have a requirement in "V1.1 Encoding and Sanitization Architecture" (preferred) or in "V1.3 Sanitization" to say:
Verify that if sanitization is chosen as a defense method, it is accepted by "business logic rules" to make automatic modifications to the input, as changing the data removes data integrity.
The wording should be improved, hopefully it it is good enough to explain the idea.
One option is also to move to the documented security decisions with this.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the raw .md files in the 5.0 tree, especially the sections titled "V1.1 Encoding and Sanitization Architecture" and "V1.3 Sanitization". Read the 61-comment discussion and the documented security decisions before proposing wording; done means the placement and requirement text have community agreement.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100