OWASP / OWASP/www-project-api-security-testing-framework

DVGA row 19: brute-force check not wired into GraphQL test case

Open
#117 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
Java
Stars
150
Forks
41
Avg merge
2d 5h
Merged PRs (30d)
3

Description

Tracked in docs/TRACEABILITY.md, DVGA row 19.

testBruteForceLockout (added in #97) lives in BrokenAuthenticationTestCase and is REST-oriented/path-pattern-gated. DVGA's "Weak Password (Brute Force)" vulnerability is on a GraphQL argument (systemDiagnostics), never reached. Needs a GraphQL-shaped equivalent.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with docs/TRACEABILITY.md row 19 and inspect testBruteForceLockout in BrokenAuthenticationTestCase, including the REST-oriented path-pattern gating. Then examine how the GraphQL systemDiagnostics argument is exercised in the test cases. Done means a GraphQL-shaped brute-force lockout check covers the DVGA vulnerability and the relevant GraphQL test case reaches it.

Written by the indexing model from the issue text.

Assessment

Tech stack
graphql, java
Domain
api, security, testing-qa
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.