Uploaded image for project: 'FHIR Specification Feedback'
  1. FHIR Specification Feedback
  2. FHIR-32205

Inputs as code should not be executed

    XMLWordPrintableJSON

Details

    • Icon: Change Request Change Request
    • Resolution: Persuasive
    • Icon: Highest Highest
    • SMART on FHIR (FHIR)
    • 2.0.0
    • FHIR Infrastructure
    • STU
    • Overview
    • 1.2.1
    • Hide

      Update: An app SHALL NOT execute any inputs it receives as code.

      To read: An app SHALL NOT execute untrusted user-supplied inputs as code.

      Show
      Update: An app SHALL NOT execute any inputs it receives as code. To read: An app SHALL NOT execute untrusted user-supplied inputs as code.
    • Gino Canessa/Yunwei Wang: 13-0-0
    • Clarification
    • Non-substantive

    Description

      • An app SHALL NOT execute any inputs it receives as code.

      This sentence is unclear. It could be read that an app is not allowed to execute any code it receives. This makes modern webapps impossible. Please clarify

      Attachments

        Activity

          People

            carl-anderson-msft Carl Anderson (Inactive)
            bvdh Bas van den Heuvel
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: