Skip to content

Additional configuration recommendations for API7:2023 Security Misconfiguration #104

@securitylevelup

Description

@securitylevelup

The topic of Security Misconfiguration is broad and can easily turn into a large checklist of things to recommend. That said, is it beneficial to at least add several configuration recommendations in the main content such as:

  • Implementing HSTS (HTTP Strict Transport Security)
  • Configuring proper Allow Origin / X-Frame-Options headers
  • Verifying Content-Type: application/graphql headers for GraphQL requests and blocking other or missing content-types.

Especially with the growth in GraphQL usage, I would recommend more examples and focus on protecting against GraphQL attacks.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions