Skip to content
This repository has been archived by the owner on Aug 27, 2024. It is now read-only.

Use configurable HTTP request body buffer size in Azure Event Grid subscription validation #184

Open
stijnmoreels opened this issue Sep 14, 2021 · 0 comments
Labels
enhancement All issues related to enhancement of a current feature event-grid-events All issues related to Azure Event Grid events event-grid-webapi-security All issues related to Azure Event Grid Web API security good first issue Good for newcomers
Milestone

Comments

@stijnmoreels
Copy link
Member

stijnmoreels commented Sep 14, 2021

Is your feature request related to a problem? Please describe.
We provide the capability to validate the Azure Event Grid subscription. This includes reading the entire HTTP request body. This can lead to problems when an unexpected large malicious body is being sent.

What feature would you like to have?
We should consider using a request buffer size to make sure we set the boundaries for the expected request body.

Additional context
References with TODO

@stijnmoreels stijnmoreels added enhancement All issues related to enhancement of a current feature event-grid-events All issues related to Azure Event Grid events labels Sep 14, 2021
@stijnmoreels stijnmoreels added this to the v3.2 milestone Sep 14, 2021
@stijnmoreels stijnmoreels added the event-grid-webapi-security All issues related to Azure Event Grid Web API security label Sep 14, 2021
@stijnmoreels stijnmoreels changed the title Use configurable request body buffer size in Azure Event Grid subscription validation Use configurable HTTP request body buffer size in Azure Event Grid subscription validation Sep 14, 2021
@stijnmoreels stijnmoreels added the good first issue Good for newcomers label Dec 20, 2021
@stijnmoreels stijnmoreels modified the milestones: v3.2, v3.3 Jan 7, 2022
@stijnmoreels stijnmoreels modified the milestones: v3.3, v3.4 Dec 1, 2022
@stijnmoreels stijnmoreels modified the milestones: v3.4, v4.1 Mar 15, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
enhancement All issues related to enhancement of a current feature event-grid-events All issues related to Azure Event Grid events event-grid-webapi-security All issues related to Azure Event Grid Web API security good first issue Good for newcomers
Projects
None yet
Development

No branches or pull requests

1 participant