Skip to content

docs(dev): add crypto APIs, unserialize and CSV injection to security.rst - #15710

Open
whoalin1 wants to merge 1 commit into
nextcloud:masterfrom
whoalin1:docs-security-rst-crypto-unserialize-csv
Open

whoalin1 wants to merge 1 commit into
nextcloud:masterfrom
whoalin1:docs-security-rst-crypto-unserialize-csv

Conversation

@whoalin1

@whoalin1 whoalin1 commented Oct 6, 2026 •

Copy link
Copy Markdown

Summary

Updates developer_manual/digging_deeper/security.rst per #15681:

  • Replace the Trusted-domain \OC::$server->get() example with constructor injection of ITrustedDomainHelper.
  • Document short DI examples for OCP\Security\ICrypto, ISecureRandom, and IHasher.
  • Warn against unserialize() on user-influenced data; prefer JSON.
  • Document CSV/spreadsheet formula-injection neutralization for cells starting with =, +, -, or @.

Closes #15681

Test plan

  • Sphinx build of the developer manual succeeds for the security page
  • Trusted-domain example uses constructor DI (no \OC::$server)
  • ICrypto / ISecureRandom / IHasher each have a short injectable example
  • Deserialization section says never unserialize user data; use JSON
  • CSV section documents neutralizing =, +, -, @ cell prefixes

AI disclosure

This PR was drafted with the help of AI coding assistants (Cursor agents / LLM-based tools), including the description. I am responsible for it and happy to rework anything that doesn't fit.

All commits carry an Assisted-by: Cursor:grok-4.7 trailer.

….rst

Assisted-by: Cursor:grok-4.7
Signed-off-by: whoalin1 <[email protected]>
@whoalin1
whoalin1 force-pushed the docs-security-rst-crypto-unserialize-csv branch from b160e0d to 04eb730 Compare October 9, 2026 14:12

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Developer manual: add crypto APIs, unserialize and CSV injection to security.rst

1 participant