mirror of
https://github.com/microsoft/BCQuality.git
synced 2026-10-05 06:36:55 +01:00
New remedial article for spotting when AL calls an endpoint that does not authenticate itself to the client (bare HttpClient.Get, blank SOAP SecretText, post-DisableHttpsCheck HTTP) and requires the response to be size-, schema-, and request/response-integrity-validated before it is trusted. Includes the BC-specific false-positive clarifications (platform buffers the full body, so an in-AL size check after buffering is correct; no DNS-rebinding/bounded-read demand; HTTPS not always enforceable) plus good/bad AL samples. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
23 lines
1,022 B
AL
23 lines
1,022 B
AL
codeunit 50541 "Sec Sample UnauthResp Bad"
|
|
{
|
|
procedure IsVatNumberValid(RequestedCountryCode: Text; RequestedVatNumber: Text): Boolean
|
|
var
|
|
HttpClient: HttpClient;
|
|
Response: HttpResponseMessage;
|
|
JsonResponse: JsonObject;
|
|
JsonToken: JsonToken;
|
|
Content: Text;
|
|
begin
|
|
// Anti-pattern: the endpoint is unauthenticated, yet the response is trusted with no
|
|
// size cap, no schema check, and no request-to-response integrity check.
|
|
HttpClient.Get('http://vat-service.example/check?cc=' + RequestedCountryCode + '&vat=' + RequestedVatNumber, Response);
|
|
Response.Content().ReadAs(Content);
|
|
JsonResponse.ReadFrom(Content);
|
|
|
|
// Trusts valid=true for ANY input: a spoofed or MITM response that omits the echoed
|
|
// countryCode/vatNumber is accepted as valid for whatever number was requested.
|
|
if JsonResponse.Get('valid', JsonToken) then
|
|
exit(JsonToken.AsValue().AsBoolean());
|
|
exit(false);
|
|
end;
|
|
}
|