mirror of
https://github.com/microsoft/BCQuality.git
synced 2026-10-06 23:26:55 +01:00
Add security knowledge: validate unauthenticated endpoint responses
New remedial article for spotting when AL calls an endpoint that does not authenticate itself to the client (bare HttpClient.Get, blank SOAP SecretText, post-DisableHttpsCheck HTTP) and requires the response to be size-, schema-, and request/response-integrity-validated before it is trusted. Includes the BC-specific false-positive clarifications (platform buffers the full body, so an in-AL size check after buffering is correct; no DNS-rebinding/bounded-read demand; HTTPS not always enforceable) plus good/bad AL samples. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
parent
841b4e7cab
commit
2c45021cb3
3 changed files with 91 additions and 0 deletions
|
|
@ -0,0 +1,23 @@
|
|||
codeunit 50541 "Sec Sample UnauthResp Bad"
|
||||
{
|
||||
procedure IsVatNumberValid(RequestedCountryCode: Text; RequestedVatNumber: Text): Boolean
|
||||
var
|
||||
HttpClient: HttpClient;
|
||||
Response: HttpResponseMessage;
|
||||
JsonResponse: JsonObject;
|
||||
JsonToken: JsonToken;
|
||||
Content: Text;
|
||||
begin
|
||||
// Anti-pattern: the endpoint is unauthenticated, yet the response is trusted with no
|
||||
// size cap, no schema check, and no request-to-response integrity check.
|
||||
HttpClient.Get('http://vat-service.example/check?cc=' + RequestedCountryCode + '&vat=' + RequestedVatNumber, Response);
|
||||
Response.Content().ReadAs(Content);
|
||||
JsonResponse.ReadFrom(Content);
|
||||
|
||||
// Trusts valid=true for ANY input: a spoofed or MITM response that omits the echoed
|
||||
// countryCode/vatNumber is accepted as valid for whatever number was requested.
|
||||
if JsonResponse.Get('valid', JsonToken) then
|
||||
exit(JsonToken.AsValue().AsBoolean());
|
||||
exit(false);
|
||||
end;
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue