benaadams / System.Ben

Who says you can't be super fast and super secure
MIT License
142 stars 23 forks source link

SUPER SERIOUS SECURITY ISSUE #2

Closed blowdart closed 7 years ago

blowdart commented 7 years ago

Missing punctuation means the reader doesn't know when to pause, inflect or indeed stop reading, causing either resource exhaustion because there's no comma to induce the user to breath, or a local DoS because the sentence never ends.

blowdart commented 7 years ago

WHY HAVE YOU NOT FIXED THIS YET?

ALSO WHERE IS MY BUG BOUNTY?

benaadams commented 7 years ago

We are assessing whether this aligns with the stated goals of the project; but are currently suffering from reading exhaustion.

blowdart commented 7 years ago

YOU SUCK

benaadams commented 7 years ago

Reverted. Do you have tests?

blowdart commented 7 years ago

Sure, they're on the tip of my finger. This finger to be precise. 🖕

Also everyone knows you should only test the public API surface, so my PR contains the appropriate number of tests for that API. This is TDD 101 Ben.

benaadams commented 7 years ago

Good point can you make PR again?

benaadams commented 7 years ago

Though you'll have to rebase...

blowdart commented 7 years ago

No it's obvious you don't understand security at all or the genius of my PR and I no longer want to be associated with you, your beard or your cardigans.

GOOD DAY SIR.