polymath-apps icon indicating copy to clipboard operation
polymath-apps copied to clipboard

Server-side validation of values in offchain API

Open monitz87 opened this issue 7 years ago • 0 comments

Right now offchain merely validates that the values sent to its API by the client are of the correct type. It would be better to implement validation of the values as well. While the ddos middleware and signature verification already protect the app from the majority of potential attacks, theoretically (although this is very unlikely) somebody could still slowly pollute our database with gibberish. These validations would also grant further insurance against changes in the client that may break the API in obscure ways.

monitz87 avatar Oct 03 '18 02:10 monitz87