Skip to content

Developer manual: add crypto APIs, unserialize and CSV injection to security.rst #15681

Description

@miaulalala

developer_manual/digging_deeper/security.rst is missing a few basics, and one example uses private API.

  • Add short sections with examples for OCP\Security\ICrypto, ISecureRandom and IHasher (currently only listed in the DI docs).
  • Add "don't unserialize() user-influenced data, use JSON".
  • Add CSV/spreadsheet export: neutralise cells starting with =, +, - or @ (formula injection).
  • The ITrustedDomainHelper example (around line 102) uses \OC::$server->get(), which is private. Show constructor injection instead.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions