{"id":1254,"date":"2020-02-18T09:39:35","date_gmt":"2020-02-18T09:39:35","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/anonymousunlimitedstring\/"},"modified":"2021-07-30T09:09:53","modified_gmt":"2021-07-30T09:09:53","slug":"anonymousunlimitedstring","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/anonymousunlimitedstring","title":{"rendered":"Unlimited string attributes should not be editable by anonymous users"},"content":{"rendered":"\n<p> Released in version 1.6 (03 March 2020) <\/p>\n\n\n\n<p>Otherwise, a malicious agent could set a very long value for the attribute causing the database to run out of space.<\/p>\n\n\n\n<p><strong>Non-compliant example:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"618\" height=\"597\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-15.png\" alt=\"\" class=\"wp-image-1256\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-15.png 618w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2020\/02\/image-15-480x464.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 618px, 100vw\" \/><\/figure>\n\n\n\n<p> *assuming that <em>AnonymousUserModuleRole<\/em> is a module role that is related to the project role for anonymous users in the app. <\/p>\n\n\n\n<p><strong>Compliant example:<\/strong><\/p>\n\n\n\n<p>No write access or the string length should be limited.<\/p>\n","protected":false},"featured_media":0,"parent":96,"menu_order":15,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-1254","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1254"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1254"}],"version-history":[{"count":2,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1254\/revisions"}],"predecessor-version":[{"id":1258,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1254\/revisions\/1258"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"User roles with a certain amount of module roles should be checked for security","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/checksecurityrole","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/500"}],"prev":[{"title":"Security should be enabled and set to Production","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securitylevel","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/243"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1254"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=1254"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}