// foundations · 01 / 09
Trust boundaries
Never trust client input
Anything crossing into your process from outside is hostile until proven otherwise: HTTP params, headers, cookies, files, JSON, MQ messages.
- Untrusted — request · file · token claims you didn't mint
- Validate — type · length · allowlist
- Use safely — parameterize · encode · authorize
- Sink — SQL · HTML · shell · filesystem
- Source — where data enters
- Sink — where it becomes dangerous
- Allowlist — prefer over blocklist
- Fail closed — reject on doubt
// check yourself
Which is safest default for a path segment from the user?