Josh Grossman
Josh Grossman
I think this is a good question which will really depend on the outcome of #1127
In the meantime, @coderpatros what sort of requirements would you expect to see in relation to this?
Note that I made another comment on https://github.com/OWASP/ASVS/issues/1127#issuecomment-1193352560
Which of the following problem options are we suggesting that this is: 1. An Authorization problem where the user is receiving data in the API that they should not have...
Hi @Sjord do you think you could prepare a PR for this?
Seems this was resolved by #1240
@elarlang I like the concept of ensuring that these sorts of lists are explicitly documented and I agree that this sounds like a V1 control. Do you want to draft...
@elarlang let me know if you are able to draft something :)
@elarlang where are we with the original part of this issue, are you going to draft something?
Please see my question in the PR