Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Secure Coding V10 - Sanity Check Comments/Suggestions for v.5.0 #2594

Open
csfreak92 opened this issue Feb 10, 2025 · 1 comment
Open

Secure Coding V10 - Sanity Check Comments/Suggestions for v.5.0 #2594

csfreak92 opened this issue Feb 10, 2025 · 1 comment
Labels
1) Discussion ongoing Issue is opened and assigned but no clear proposal yet V10 _5.0 - prep This needs to be addressed to prepare 5.0

Comments

@csfreak92
Copy link
Collaborator

Chapter V10 - Secure Coding

Here are a few things I observed reviewing this chapter for v.5.0 for sanity check related to #2582:

V10.4 Defensive Coding
Needs some paragraph describing this section. For consistency across all subsections in ASVS.

V10.5 Security Architecture
Needs some paragraph describing this section. For consistency across all subsections in ASVS.

Suggestion:

10.4.6 [ADDED] Verify that the application is able to discern and utilizes the user's true IP address to provide for sensitive functions, including rate limiting and logging.

This requirement doesn't feel like it should belong here in this chapter though. We may need to check out where else it could fit. Seems odd for it to be here.

@elarlang
Copy link
Collaborator

elarlang commented Feb 10, 2025

This requirement doesn't feel like it should belong here

Can you explain, why it does not fit? Also see #1389

@tghosth tghosth added 1) Discussion ongoing Issue is opened and assigned but no clear proposal yet _5.0 - prep This needs to be addressed to prepare 5.0 V10 and removed 1) Discussion ongoing Issue is opened and assigned but no clear proposal yet _5.0 - prep This needs to be addressed to prepare 5.0 labels Feb 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1) Discussion ongoing Issue is opened and assigned but no clear proposal yet V10 _5.0 - prep This needs to be addressed to prepare 5.0
Projects
None yet
Development

No branches or pull requests

3 participants