{"id":2860,"date":"2022-11-23T10:42:03","date_gmt":"2022-11-23T10:42:03","guid":{"rendered":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securityrestwithtemplate"},"modified":"2023-01-10T08:41:13","modified_gmt":"2023-01-10T08:41:13","slug":"securityrestwithtemplate","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securityrestwithtemplate","title":{"rendered":"REST calls with templates should be escaped"},"content":{"rendered":"\n<p>A string template as body for a REST call (or a web service call for that matter) can be used for an injection attack if the template has parameters that are not properly escaped. If somebody can influence the value of the parameter the resulting JSON can be manipulated.<\/p>\n\n\n\n<p>This rule detects the places where a string template is used in a REST or web service call and the string template has parameters. This rule will not detect if the parameters are properly escaped or can be changed by the user. To solve this violation you can refactor to use an export mapping or escape the parameters and annotate to prevent the violation.<\/p>\n\n\n\n<p><strong>Non-compliant example:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"641\" height=\"580\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/11\/image.png\" alt=\"\" class=\"wp-image-2862\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/11\/image.png 641w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2022\/11\/image-480x434.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 641px, 100vw\" \/><figcaption><em>Json code in the attribute determins the request.<\/em><\/figcaption><\/figure>\n\n\n\n<p><strong>Compliant example:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"704\" height=\"392\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2023\/01\/image.png\" alt=\"\" class=\"wp-image-2892\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2023\/01\/image.png 704w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2023\/01\/image-480x267.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 704px, 100vw\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"629\" height=\"443\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2023\/01\/image-1.png\" alt=\"\" class=\"wp-image-2893\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2023\/01\/image-1.png 629w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2023\/01\/image-1-480x338.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 629px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>Escaping:<\/strong><\/p>\n\n\n\n<p>To escape a string for use in JSON a java action can be written and a java JSON library can be used. For example using Google GSON use this code snippet where InputParameter is a string parameter from the Mendix java action:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\t\tif (InputParameter==null) return JsonNull.INSTANCE.toString();\n\t\tJsonPrimitive jp = new JsonPrimitive(InputParameter); \/\/ this does the escaping!\n\t\tString escaped = jp.toString(); \/\/ do not use getAsString as it unescapes.\n\t\treturn escaped.substring(1, escaped.length()-1); \/\/ since toString places 2 double quotes.<\/code><\/pre>\n","protected":false},"featured_media":0,"parent":96,"menu_order":28,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-2860","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2860"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2860"}],"version-history":[{"count":3,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2860\/revisions"}],"predecessor-version":[{"id":2894,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2860\/revisions\/2894"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"Page URL's should be checked (Dec 2022)","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securitystrictpageurl","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2864"}],"prev":[{"title":"Use user libraries without security vulnerabilities","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securityjarvulnerability","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2145"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2860"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=2860"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}