Skip to content

Create bandit.yml#358

Open
shuarob wants to merge 1 commit intoOWASP:masterfrom
shuarob:shuarob-patch-bandit.yaml
Open

Create bandit.yml#358
shuarob wants to merge 1 commit intoOWASP:masterfrom
shuarob:shuarob-patch-bandit.yaml

Conversation

@shuarob
Copy link
Copy Markdown

@shuarob shuarob commented Dec 5, 2025

Implementing bandit to trigger any vulnerability issues.

Implementing bandit to trigger any vulnerability issues.
iampava pushed a commit to Initech-cantina/NodeGoat that referenced this pull request Mar 18, 2026
Replace specific error messages ("Invalid username", "Invalid password",
"User name already in use") with generic alternatives that do not reveal
whether an account exists. This hardens both the login and signup flows
against unauthenticated username enumeration.

Addresses WEB-9 / Clarion alert OWASP#358.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant