adoptium / adoptium/aqa-test-tools
Enhance getData API
Open
- Dominant language
- Jupyter Notebook
- Stars
- 33
- Forks
- 97
- Avg merge
- 7h 9m
- Merged PRs (30d)
- 5
Description
https://github.com/adoptium/aqa-test-tools/blob/master/TestResultSummaryService/routes/getData.js is built from user-provided data. We need to add sufficient sanitization.
For details, see GitHub Code Scanning / CodeQL at https://github.com/adoptium/aqa-test-tools/pull/732
Contributor guide
Research direction
Start with TestResultSummaryService/routes/getData.js and the CodeQL findings referenced in pull/732. Trace how user-provided data reaches the getData API, apply the sanitization required by those findings, and verify that the reported security issue is resolved.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- api, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100