Added a function for LDAP input sanitization.#170
Open
Heikkips wants to merge 1 commit intoGluuFederation:version_3.1.6from
Open
Added a function for LDAP input sanitization.#170Heikkips wants to merge 1 commit intoGluuFederation:version_3.1.6from
Heikkips wants to merge 1 commit intoGluuFederation:version_3.1.6from
Conversation
|
@yurem ^ |
Contributor
|
I'm not sure oxCore is the right place to do this. You may end up sanitizing all input, not just input from the end user. Personally, I would do this in the authn interception script. Futhermore, I think Weld has some built in protection for escaping user input. |
Contributor
|
Line from oxAuth builds filter like According to UnboidID SDK docs it already has sanitizing support: Can you provide example of invalid input to allow us double check it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Added a function for sanitizing input strings before LDAP operations.
@link https://www.owasp.org/index.php/LDAP_injection
This can be used to sanitize the input of several oxAuth endpoints e.g.: