FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Separate out canonicalization from the Encoder component · Issue #18 · ESAPI/esapi-java · GitHub

Repository navigation

Separate out canonicalization from the Encoder component #18

Description

The ESAPI Validator component uses the various Encoder.canonicalize methods, which creates a tight coupling between the Validator and Encoder. We want to avoid that for ESAPI 3, therefore I am proposing to create a lightweight Canonicalizer component and move the Encoder.canonicalize methods to it. That should minimize dependencies for the Validator. ESAPI 3, since it is a major change and thus is permitted to break interfaces, would be a good time to do that.

Activity

  1. xeno6696 commented on Jul 30, 2023

    I totally agree. As I was thinking about how to help Jeff's question, at one point I considered adjusting the sensitivity of the multiple encoding (I believe there's a parameter for that in esapi.properties) and then quickly realized that its a global setting.

    No joy there.

    @jeremiahjstacey In thinking about how to attack a canonicalizer in the future, I'm thinking that a builder pattern probably looks best? I know that's the path that the HTML Sanitizer uses.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions


      Back | FazBrowse Home | New Git URL