akto-api-security / akto

Proactive, Open source API security → API discovery, Testing in CI/CD, Test Library with 150+ Tests, Add custom tests, Sensitive data exposure
https://www.akto.io/
MIT License
976 stars 190 forks source link

⛏️ Write test to identify relay global object for GraphQl APIs #112

Open Ankita28g opened 1 year ago

Ankita28g commented 1 year ago

💭 Introduction: https://wundergraph.com/blog/the_complete_graphql_security_guide_fixing_the_13_most_common_graphql_vulnerabilities_to_make_your_api_production_ready#8.-relay-global-object-identification-vulnerability

📚 Reading You can find a detailed documentation of test editor rules here Find 100+ examples of YAML tests here

✅ Task summary:

✌🏻 Hints: You can build the yaml template by referring this link

🙋🏼‍♂️ Questions: If you have questions, need any help, or just want to hang out, make sure to join us on our Discord server.

ShikhaaT44 commented 10 months ago

I'm interested in working on this issue. Can I be assigned?

avneesh-akto commented 10 months ago

I've assigned it to you, @ShikhaaT44 . Happy hacking! Feel free to join our Discord if you need assistance.

PS: Make sure to test the YAML file on sample API before you open a PR

ShikhaaT44 commented 10 months ago

@avneesh-akto , i would like to get unassigned from this issue due to some technical issues in my machine while setting up the project environment.

avneesh-akto commented 10 months ago

done