Reducing user input validation code in web applications using Pex extension
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F68407700%3A21230%2F14%3A00222526" target="_blank" >RIV/68407700:21230/14:00222526 - isvavai.cz</a>
Result on the web
<a href="http://dl.acm.org/citation.cfm?id=2659532.2659633" target="_blank" >http://dl.acm.org/citation.cfm?id=2659532.2659633</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1145/2659532.2659633" target="_blank" >10.1145/2659532.2659633</a>
Alternative languages
Result language
angličtina
Original language name
Reducing user input validation code in web applications using Pex extension
Original language description
Validation of user input data is very important in web application. Not only it protects the system from various exploits, but it also improves the user experience. User immediately sees what values are missing or are not valid and should be fixed. It isimportant to validate code on client side in the browser, but that does not mean that the validation on server side can be omitted. The golden rule of the web applications is not to trust user input and validate code on server side as well. The user input validation is therefore duplicated - it validates the input values first on client side using JavaScript before the data is sent to server and then the received data is validated again on the server side. Changes made to the validation code must be synchronized in code on both sides. All implementations must be also unit tested, multiple sets of unit tests must be created and maintained. We will describe how we extended white-box testing tool Pex to generate user input validation code
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
IN - Informatics
OECD FORD branch
—
Result continuities
Project
—
Continuities
S - Specificky vyzkum na vysokych skolach
Others
Publication year
2014
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
ACM International Conference Proceeding Series, Volume 883
ISBN
978-1-4503-2753-4
ISSN
—
e-ISSN
—
Number of pages
7
Pages from-to
302-308
Publisher name
Bulgarian Chapter of ACM
Place of publication
Rousse
Event location
Ruse
Event date
Jun 27, 2014
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
—