api-platform / api-platform/core

Input size validation

Ouverte
#7,978 5 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
Langage dominant
PHP
Étoiles
2.6k
Forks
980
Merge moyen
2 j 5 h
PR mergées (30 j)
48

Description

Hello,

While browsing the OWASP website, I've stumbled upon [the following interesting recommendation](https://www.owasp.org/index.php/REST_Security_Cheat_Sheet#Input_validation) that isn't, in my knowledge, covered by the API Platform:

> Define an appropriate request size limit and reject requests exceeding the limit with HTTP response status 413 Request Entity Too Large

I believe it would be quite achievable to provide a listener checking for the request content size against a configured threshold and return an appropriate response when necessary.

Is this already covered in API platform?
If not, why?

If that's of interest, I'd be happy working on the implementation.

Best Regards.

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.