What would you like added?
Briefly describe the topic of the new content. Is this a new section or an addition to an existing topic?
Adding a new topic on GraphQL API testing, which might be a part of API testing - https://github.com/OWASP/wstg/issues/492
Fixes OWASP/wstg#492
Would you like to be assigned to this issue?
Check the box if you will submit a PR to add the proposed content. Please read CONTRIBUTING.md.
Actually, I'd later assign this to my colleague who is going to contribute directly for this topic. Please assign me for now if it sounds ok.
Sounds good to me.
The ZAP team has a student working on GraphQL support as part of GSoC: https://akshathkothari.com/gsoc/
There's a vuln app here that might be good for PoCs or examples: https://github.com/righettod/poc-graphql
thanks @kingthorin, can you assign it to 1Oreo, who will provide a draft :)
I can't see any such user, please have them comment on the issue.
Hey, commenting to your request, Jeremy sent me the link, I'll be contributing since we have done some research on GraphQL in the last couple of weeks. Thank you.
@kingthorin thanks. great work. we are looking at it.
@kingthorin I'm starting to work on the issue and wanted to ask about which folder it should reside in, as well as ID number etc'.
I can also put the file in the main folder (since I saw there are some newer files there?).
Thank you for your comments, I'll include them in the guide.
API testing is going to be a special case. If it's not going to be integrated inside of other tests, I believe the best action would be to create a new chapter, chapter 12, and plug in API testing with references possibly to other sections where need be. If a new chapter is a bad idea, but we still need it to be its own section, an appendix will have to be our go to.
What do you guys think?
@ThunderSon I agree, that is why I brought it up.
I saw a reference in issue 492, and if there will be more API testing with commonly used technologies, creating a new chapter which will include many APIs to test, will be the way to go IMO.
I'll create a new folder in the repo I forked and when we're done we'll see how to best place it.
Thank you for the fast comment.
+1 to creating a new chapter in the same way as ASVS has a separate one (V13)
Created the PR for this issue and would like to get your review on the guide (#577) .
Well received, thanks @1Oreo !
@1Oreo I hope this was a lovely experience with the team! If you have any feedback for the team (positive or negative so we can improve and know our strength points), please send it to my email on elie.[email protected]
Closed by #577
Most helpful comment
Hey, commenting to your request, Jeremy sent me the link, I'll be contributing since we have done some research on GraphQL in the last couple of weeks. Thank you.