api-platform / api-platform/core

Input size validation

オープン
#7,978 コメント 5 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
PHP
スター
2.6k
フォーク
980
平均マージ
2日 5時間
マージ済み PR(30日)
48

説明

Hello,

While browsing the OWASP website, I've stumbled upon [the following interesting recommendation](https://www.owasp.org/index.php/REST_Security_Cheat_Sheet#Input_validation) that isn't, in my knowledge, covered by the API Platform:

> Define an appropriate request size limit and reject requests exceeding the limit with HTTP response status 413 Request Entity Too Large

I believe it would be quite achievable to provide a listener checking for the request content size against a configured threshold and return an appropriate response when necessary.

Is this already covered in API platform?
If not, why?

If that's of interest, I'd be happy working on the implementation.

Best Regards.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。