alphagov / learningtime-ad-sem1-postcode-geocoder

Early talent assigned learning time, Antoni's Semester 1 project for creating a postcode geolocation app.
2 stars 0 forks source link

Add validating to protect against Server-side request forgery #51

Open antoni-devlin opened 1 year ago

antoni-devlin commented 1 year ago

Interesting yeah I just looked through that too. I agree with you @antoni-devlin but let's also think about how you'd mitigate this?

You don't have to come up with a solution, but might be good to make a TODO.md or a card that outlines what you think you could do about this problem?

I wonder for instance if we could do anything to validate that input 🤔

_Originally posted by @huwd in https://github.com/alphagov/learningtime-ad-sem1-postcode-geocoder/pull/47#discussion_r1224184004_