../foundations

// foundations · 01 / 09

Trust boundaries

Never trust client input

Anything crossing into your process from outside is hostile until proven otherwise: HTTP params, headers, cookies, files, JSON, MQ messages.

  • Untrusted — request · file · token claims you didn't mint
  • Validate — type · length · allowlist
  • Use safely — parameterize · encode · authorize
  • Sink — SQL · HTML · shell · filesystem
  • Source — where data enters
  • Sink — where it becomes dangerous
  • Allowlist — prefer over blocklist
  • Fail closed — reject on doubt

// check yourself

Which is safest default for a path segment from the user?

Secure Java development — Prashant Dangi