Security fixes: add app_good.py, requirements, tests, README; move to… #4
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Suggested PR title
Secure rewrite: add app_good.py, good.db, tests, and README; fix vulnerable endpoints
Suggested PR description
Summary
app_good.py) usinggood.db.Changes
app_good.py,requirements.txt,test_endpoints.pyREADME.mdwith setup/run/test instructionsgood.dbwith bcrypt-hashed users (alice admin, bob user)Security hardening highlights
/users/find/auth/idor/xss/bank/transferviaX-CSRF-Tokensecure_filename, extension allowlist, size limitsdefusedxmlsubprocess.run([...], shell=False)for pingeval; tiny integer-only evaluatorcompare_digestfor/sig/verifyHow to run
pip install -r requirements.txtpython app_good.pygood.dband restartTests
python test_endpoints.pyNotes
SECRET_KEY,HMAC_SECRET,BASE_URL(optional for tests)Checklist
good.dbRepo:
https://github.com/saad22598/secure-coding