Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Injection attacks? #131

Open
andyhd opened this issue Jul 28, 2023 · 0 comments
Open

Injection attacks? #131

andyhd opened this issue Jul 28, 2023 · 0 comments
Assignees
Labels
question Further information is requested

Comments

@andyhd
Copy link
Contributor

andyhd commented Jul 28, 2023

Could an attacker inject malicious code in place of the UID or consent payload?

Injecting a malicious UID in the cookie or URL parameter should be protected against by SQLAlchemy.

Currently, the consent payload is probably safe due to FastAPI and Pydantic. But if we need to make the schema more flexible, we need to be careful.

@andyhd andyhd added the question Further information is requested label Jul 28, 2023
@andyhd andyhd self-assigned this Jul 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

1 participant