Add note about sanitizer and consider methods to acquire a centrally configured sanitizer
Open
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 28
- Forks
- 25
- Avg merge
- 4d 22h
- Merged PRs (30d)
- 20
Description
As discussed in https://github.com/USACE/cwms-data-api/pull/631
Its not always easy or convenient to pull a sanitizer out of request context.
Its also possible that we need to investigate html sanitizer vs json/xml sanitizer
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the discussion in pull request #631 and trace how sanitizers are obtained from request context. The issue names no files or tests; completion would require documenting sanitizer expectations and reaching a decision on centrally configured acquisition and HTML versus JSON/XML sanitization.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- api, backend, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100