8000 Add defensive programming section to security guide · Issue #176 · 18F/frontend · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
This repository was archived by the owner on Feb 15, 2020. It is now read-only.
This repository was archived by the owner on Feb 15, 2020. It is now read-only.
Add defensive programming section to security guide #176
Open
@msecret

Description

@msecret

In order for 18F developers to have a practical understanding of what defensive programming is and the threats of untrusted user data, there should be a section in the security guide about it.

It should:

  • Include information on understanding threats posed by untrusted, user-provided data
  • Either include a link to information about output encoding, or written information
  • The guidance should include practical examples and information on how a team can actually continue this practice on a real team, including tools to use.
  • The link should be reviewed by 18F security lead

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      0