dc4eu / vc

European Wallet
BSD 2-Clause "Simplified" License
6 stars 9 forks source link

Missing request parameter validation in DELETE /document/identity #82

Closed JuAlMan closed 2 months ago

JuAlMan commented 3 months ago

Using image docker.sunet.se/dc4eu/apigw:apiv28

In the current implementation there seems to be no request parameter validation, it is for example possible to submit an empty request object.

As all four parameters are required, a validation error should be returned if one or more parameters are missing.

masv3971 commented 2 months ago

Should be fixed with, https://github.com/dc4eu/vc/commit/e1ea46f3d3bd5e1393e1686af6d9c465efd1d4ca