bcquality/microsoft/knowledge/security/validate-unauthenticated-response-before-use.bad.al
Djordje Cenic 2c45021cb3 Add security knowledge: validate unauthenticated endpoint responses
New remedial article for spotting when AL calls an endpoint that does not
authenticate itself to the client (bare HttpClient.Get, blank SOAP SecretText,
post-DisableHttpsCheck HTTP) and requires the response to be size-, schema-, and
request/response-integrity-validated before it is trusted. Includes the
BC-specific false-positive clarifications (platform buffers the full body, so an
in-AL size check after buffering is correct; no DNS-rebinding/bounded-read demand;
HTTPS not always enforceable) plus good/bad AL samples.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-09-15 13:16:53 +02:00

23 lines
1,022 B
AL

codeunit 50541 "Sec Sample UnauthResp Bad"
{
procedure IsVatNumberValid(RequestedCountryCode: Text; RequestedVatNumber: Text): Boolean
var
HttpClient: HttpClient;
Response: HttpResponseMessage;
JsonResponse: JsonObject;
JsonToken: JsonToken;
Content: Text;
begin
// Anti-pattern: the endpoint is unauthenticated, yet the response is trusted with no
// size cap, no schema check, and no request-to-response integrity check.
HttpClient.Get('http://vat-service.example/check?cc=' + RequestedCountryCode + '&vat=' + RequestedVatNumber, Response);
Response.Content().ReadAs(Content);
JsonResponse.ReadFrom(Content);
// Trusts valid=true for ANY input: a spoofed or MITM response that omits the echoed
// countryCode/vatNumber is accepted as valid for whatever number was requested.
if JsonResponse.Get('valid', JsonToken) then
exit(JsonToken.AsValue().AsBoolean());
exit(false);
end;
}