OWASP / OWASP/www-project-api-security-testing-framework

crAPI row 12: NoSQL injection breadth beyond login-shaped bodies

Open
#120 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
Java
Stars
150
Forks
41
Avg merge
2d 5h
Merged PRs (30d)
3

Description

Tracked in docs/TRACEABILITY.md, crAPI row 12.

SqlNoSqlInjectionTestCase's NoSQL auth-bypass check (testDetectsNoSqlAuthBypass) only targets login-shaped bodies (username/password fields with a $ne operator). crAPI's "free coupons via NoSQL injection" challenge targets a coupon-code-shaped field with different operator injection. Broaden NoSQL payload targeting beyond the login pattern.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Read docs/TRACEABILITY.md row 12 and inspect SqlNoSqlInjectionTestCase, especially testDetectsNoSqlAuthBypass. Extend the NoSQL payload coverage beyond username/password login bodies to include coupon-code-shaped operator injection, then verify the test detects the crAPI free-coupons challenge pattern.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security, testing
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.