OWASP / OWASP/ASVS

proposal: add requirement to verify that using a sanitization is an accepted solution for that data or flow

Open
#3,346 61 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

V1 (prev V5)
Dominant language
HTML
Stars
3.6k
Forks
832
Avg merge
7h 55m
Merged PRs (30d)
4

Description

To make things related to the sanitization topic clearer, we need to be sure that sanitization as a defense is an acceptable option for the current data or process.

I think it would be good to have a requirement in "V1.1 Encoding and Sanitization Architecture" (preferred) or in "V1.3 Sanitization" to say:

Verify that if sanitization is chosen as a defense method, it is accepted by "business logic rules" to make automatic modifications to the input, as changing the data removes data integrity.

The wording should be improved, hopefully it it is good enough to explain the idea.

One option is also to move to the documented security decisions with this.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the raw .md files in the 5.0 tree, especially the sections titled "V1.1 Encoding and Sanitization Architecture" and "V1.3 Sanitization". Read the 61-comment discussion and the documented security decisions before proposing wording; done means the placement and requirement text have community agreement.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.