Тёмный
No video :(

Getting API Security Right - Philippe De Ryck - NDC Security 2022 

NDC Conferences
Подписаться 196 тыс.
Просмотров 6 тыс.
50% 1

Опубликовано:

 

27 авг 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 3   
@richardfrimpong5891
@richardfrimpong5891 2 года назад
Now that is a really really good talk. Thanks a lot Philippe De Ryck
@sCr33nSh0o71
@sCr33nSh0o71 2 года назад
what if you have endpoint user/tasks/{id} and you dont put validation if you have access to this task but when you make call to the db you use the filter task = id and userid = token.userid ?
@danfroal8057
@danfroal8057 2 года назад
too late better than never ; you waste a call to the database (sometimes costly, and it can stack up), you break single responsibility principle (data layer is not responsible for auth), you make testing, auditing and maintenance difficult (change of schema? distributed databases?). There must be even nastier and more obvious things I don't see from a security standpoint, but these reasons are already enough in terms of best practices.
Далее
🛑самое грустное видео
00:10
Просмотров 128 тыс.
C’est qui le plus fort 😂
00:18
Просмотров 10 млн
Analyzing The OWASP API Security Top 10 For Pen Testers
1:00:23
Fractal Architecture - Mark Seemann - NDC Porto 2022
53:32
5 Best Practices for Securing Your APIs
15:42
Просмотров 45 тыс.
OWASP API Security Top 10 Webinar
56:53
Просмотров 54 тыс.
🛑самое грустное видео
00:10
Просмотров 128 тыс.