[ASM] Avoid unhandled HttpRequestValidationExceptions#5943
Conversation
Datadog ReportBranch report: ❌ 1 Failed (1 Known Flaky), 364634 Passed, 2054 Skipped, 15h 33m 27.49s Total Time ❌ Failed Tests (1)
|
Execution-Time Benchmarks Report ⏱️Execution-time results for samples comparing the following branches/commits: Execution-time benchmarks measure the whole time it takes to execute a program. And are intended to measure the one-off costs. Cases where the execution time results for the PR are worse than latest master results are shown in red. The following thresholds were used for comparing the execution times:
Note that these results are based on a single point-in-time result for each branch. For full results, see the dashboard. Graphs show the p99 interval based on the mean and StdDev of the test run, as well as the mean value of the run (shown as a diamond below the graph). |
Benchmarks Report for appsec 🐌Benchmarks for #5943 compared to master:
The following thresholds were used for comparing the benchmark speeds:
Allocation changes below 0.5% are ignored. Benchmark detailsBenchmarks.Trace.Asm.AppSecBodyBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Asm.AppSecEncoderBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Asm.AppSecWafBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Iast.StringAspectsBenchmark - Same speed ✔️ More allocations
|
| Benchmark | Base Allocated | Diff Allocated | Change | Change % |
|---|---|---|---|---|
| Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑netcoreapp3.1 | 251.8 KB | 264.26 KB | 12.46 KB | 4.95% |
| Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑net6.0 | 253.15 KB | 254.56 KB | 1.41 KB | 0.56% |
| Benchmark | Base Allocated | Diff Allocated | Change | Change % |
|---|---|---|---|---|
| Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatBenchmark‑net472 | 59.55 KB | 58.9 KB | -656 B | -1.10% |
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | StringConcatBenchmark |
net6.0 | 60μs | 802ns | 7.94μs | 0 | 0 | 0 | 43.44 KB |
| master | StringConcatBenchmark |
netcoreapp3.1 | 54.3μs | 271ns | 1.15μs | 0 | 0 | 0 | 42.64 KB |
| master | StringConcatBenchmark |
net472 | 37.6μs | 96.7ns | 362ns | 0 | 0 | 0 | 59.55 KB |
| master | StringConcatAspectBenchmark |
net6.0 | 306μs | 1.72μs | 11.2μs | 0 | 0 | 0 | 253.15 KB |
| master | StringConcatAspectBenchmark |
netcoreapp3.1 | 333μs | 1.87μs | 11.7μs | 0 | 0 | 0 | 251.8 KB |
| master | StringConcatAspectBenchmark |
net472 | 290μs | 6.63μs | 64.3μs | 0 | 0 | 0 | 278.53 KB |
| #5943 | StringConcatBenchmark |
net6.0 | 60μs | 844ns | 8.39μs | 0 | 0 | 0 | 43.44 KB |
| #5943 | StringConcatBenchmark |
netcoreapp3.1 | 53.2μs | 285ns | 1.46μs | 0 | 0 | 0 | 42.64 KB |
| #5943 | StringConcatBenchmark |
net472 | 37.3μs | 178ns | 732ns | 0 | 0 | 0 | 58.9 KB |
| #5943 | StringConcatAspectBenchmark |
net6.0 | 307μs | 1.7μs | 10.8μs | 0 | 0 | 0 | 254.56 KB |
| #5943 | StringConcatAspectBenchmark |
netcoreapp3.1 | 345μs | 1.9μs | 11.7μs | 0 | 0 | 0 | 264.26 KB |
| #5943 | StringConcatAspectBenchmark |
net472 | 282μs | 5.76μs | 55.9μs | 0 | 0 | 0 | 278.53 KB |
Benchmarks Report for tracer 🐌Benchmarks for #5943 compared to master:
The following thresholds were used for comparing the benchmark speeds:
Allocation changes below 0.5% are ignored. Benchmark detailsBenchmarks.Trace.ActivityBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.AgentWriterBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.AspNetCoreBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.DbCommandBenchmark - Faster 🎉 Same allocations ✔️
|
| Benchmark | base/diff | Base Median (ns) | Diff Median (ns) | Modality |
|---|---|---|---|---|
| Benchmarks.Trace.DbCommandBenchmark.ExecuteNonQuery‑net6.0 | 1.149 | 1,345.72 | 1,170.71 |
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | ExecuteNonQuery |
net6.0 | 1.35μs | 1.31ns | 5.06ns | 0.0142 | 0 | 0 | 1.02 KB |
| master | ExecuteNonQuery |
netcoreapp3.1 | 1.72μs | 1.68ns | 6.5ns | 0.0138 | 0 | 0 | 1.02 KB |
| master | ExecuteNonQuery |
net472 | 2.02μs | 0.813ns | 2.93ns | 0.157 | 0 | 0 | 987 B |
| #5943 | ExecuteNonQuery |
net6.0 | 1.17μs | 0.694ns | 2.69ns | 0.0147 | 0 | 0 | 1.02 KB |
| #5943 | ExecuteNonQuery |
netcoreapp3.1 | 1.71μs | 1.4ns | 5.43ns | 0.0137 | 0 | 0 | 1.02 KB |
| #5943 | ExecuteNonQuery |
net472 | 1.96μs | 2.16ns | 8.09ns | 0.156 | 0 | 0 | 987 B |
Benchmarks.Trace.ElasticsearchBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | CallElasticsearch |
net6.0 | 1.19μs | 0.497ns | 1.86ns | 0.0137 | 0 | 0 | 976 B |
| master | CallElasticsearch |
netcoreapp3.1 | 1.46μs | 0.583ns | 2.1ns | 0.0132 | 0 | 0 | 976 B |
| master | CallElasticsearch |
net472 | 2.47μs | 1.59ns | 5.97ns | 0.158 | 0 | 0 | 995 B |
| master | CallElasticsearchAsync |
net6.0 | 1.35μs | 1.64ns | 6.37ns | 0.0135 | 0 | 0 | 952 B |
| master | CallElasticsearchAsync |
netcoreapp3.1 | 1.65μs | 0.594ns | 2.3ns | 0.0142 | 0 | 0 | 1.02 KB |
| master | CallElasticsearchAsync |
net472 | 2.51μs | 1.25ns | 4.67ns | 0.166 | 0 | 0 | 1.05 KB |
| #5943 | CallElasticsearch |
net6.0 | 1.14μs | 0.514ns | 1.99ns | 0.0137 | 0 | 0 | 976 B |
| #5943 | CallElasticsearch |
netcoreapp3.1 | 1.53μs | 2.05ns | 7.67ns | 0.0131 | 0 | 0 | 976 B |
| #5943 | CallElasticsearch |
net472 | 2.43μs | 2.07ns | 8.03ns | 0.158 | 0 | 0 | 995 B |
| #5943 | CallElasticsearchAsync |
net6.0 | 1.37μs | 0.899ns | 3.36ns | 0.0132 | 0 | 0 | 952 B |
| #5943 | CallElasticsearchAsync |
netcoreapp3.1 | 1.74μs | 0.762ns | 2.95ns | 0.0132 | 0 | 0 | 1.02 KB |
| #5943 | CallElasticsearchAsync |
net472 | 2.57μs | 2.07ns | 8.02ns | 0.167 | 0 | 0 | 1.05 KB |
Benchmarks.Trace.GraphQLBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | ExecuteAsync |
net6.0 | 1.34μs | 0.561ns | 2.1ns | 0.013 | 0 | 0 | 952 B |
| master | ExecuteAsync |
netcoreapp3.1 | 1.57μs | 0.783ns | 2.82ns | 0.0127 | 0 | 0 | 952 B |
| master | ExecuteAsync |
net472 | 1.73μs | 0.546ns | 2.04ns | 0.145 | 0 | 0 | 915 B |
| #5943 | ExecuteAsync |
net6.0 | 1.37μs | 1.12ns | 4.33ns | 0.0133 | 0 | 0 | 952 B |
| #5943 | ExecuteAsync |
netcoreapp3.1 | 1.66μs | 2.08ns | 8.07ns | 0.0123 | 0 | 0 | 952 B |
| #5943 | ExecuteAsync |
net472 | 1.71μs | 0.853ns | 3.31ns | 0.145 | 0 | 0 | 915 B |
Benchmarks.Trace.HttpClientBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | SendAsync |
net6.0 | 4.14μs | 0.957ns | 3.58ns | 0.0311 | 0 | 0 | 2.22 KB |
| master | SendAsync |
netcoreapp3.1 | 5.1μs | 2.15ns | 8.05ns | 0.0359 | 0 | 0 | 2.76 KB |
| master | SendAsync |
net472 | 7.75μs | 2.41ns | 9.35ns | 0.496 | 0 | 0 | 3.15 KB |
| #5943 | SendAsync |
net6.0 | 4.24μs | 2.39ns | 8.94ns | 0.0317 | 0 | 0 | 2.22 KB |
| #5943 | SendAsync |
netcoreapp3.1 | 5.15μs | 1.33ns | 5.14ns | 0.0361 | 0 | 0 | 2.76 KB |
| #5943 | SendAsync |
net472 | 7.72μs | 1.39ns | 5.19ns | 0.499 | 0 | 0 | 3.15 KB |
Benchmarks.Trace.ILoggerBenchmark - Faster 🎉 Same allocations ✔️
Faster 🎉 in #5943
Benchmark
base/diff
Base Median (ns)
Diff Median (ns)
Modality
Benchmarks.Trace.ILoggerBenchmark.EnrichedLog‑netcoreapp3.1
1.159
2,374.65
2,049.67
| Benchmark | base/diff | Base Median (ns) | Diff Median (ns) | Modality |
|---|---|---|---|---|
| Benchmarks.Trace.ILoggerBenchmark.EnrichedLog‑netcoreapp3.1 | 1.159 | 2,374.65 | 2,049.67 |
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | EnrichedLog |
net6.0 | 1.47μs | 0.435ns | 1.68ns | 0.0229 | 0 | 0 | 1.64 KB |
| master | EnrichedLog |
netcoreapp3.1 | 2.38μs | 0.732ns | 2.74ns | 0.0225 | 0 | 0 | 1.64 KB |
| master | EnrichedLog |
net472 | 2.71μs | 1.55ns | 5.99ns | 0.249 | 0 | 0 | 1.57 KB |
| #5943 | EnrichedLog |
net6.0 | 1.59μs | 0.728ns | 2.72ns | 0.0233 | 0 | 0 | 1.64 KB |
| #5943 | EnrichedLog |
netcoreapp3.1 | 2.05μs | 0.986ns | 3.69ns | 0.0215 | 0 | 0 | 1.64 KB |
| #5943 | EnrichedLog |
net472 | 2.73μs | 2.47ns | 9.55ns | 0.249 | 0 | 0 | 1.57 KB |
Benchmarks.Trace.Log4netBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | EnrichedLog |
net6.0 | 117μs | 134ns | 502ns | 0.0589 | 0 | 0 | 4.28 KB |
| master | EnrichedLog |
netcoreapp3.1 | 121μs | 386ns | 1.5μs | 0 | 0 | 0 | 4.28 KB |
| master | EnrichedLog |
net472 | 151μs | 215ns | 832ns | 0.682 | 0.227 | 0 | 4.46 KB |
| #5943 | EnrichedLog |
net6.0 | 116μs | 197ns | 762ns | 0.0581 | 0 | 0 | 4.28 KB |
| #5943 | EnrichedLog |
netcoreapp3.1 | 120μs | 156ns | 605ns | 0.061 | 0 | 0 | 4.28 KB |
| #5943 | EnrichedLog |
net472 | 150μs | 120ns | 417ns | 0.675 | 0.225 | 0 | 4.46 KB |
Benchmarks.Trace.NLogBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | EnrichedLog |
net6.0 | 3.07μs | 0.986ns | 3.69ns | 0.0305 | 0 | 0 | 2.2 KB |
| master | EnrichedLog |
netcoreapp3.1 | 4.39μs | 0.973ns | 3.77ns | 0.0305 | 0 | 0 | 2.2 KB |
| master | EnrichedLog |
net472 | 4.85μs | 1.03ns | 4.01ns | 0.32 | 0 | 0 | 2.02 KB |
| #5943 | EnrichedLog |
net6.0 | 3.05μs | 1.18ns | 4.57ns | 0.0307 | 0 | 0 | 2.2 KB |
| #5943 | EnrichedLog |
netcoreapp3.1 | 4.25μs | 1.72ns | 6.42ns | 0.0279 | 0 | 0 | 2.2 KB |
| #5943 | EnrichedLog |
net472 | 4.92μs | 1.52ns | 5.87ns | 0.32 | 0 | 0 | 2.02 KB |
Benchmarks.Trace.RedisBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | SendReceive |
net6.0 | 1.31μs | 0.747ns | 2.79ns | 0.0164 | 0 | 0 | 1.14 KB |
| master | SendReceive |
netcoreapp3.1 | 1.75μs | 0.965ns | 3.48ns | 0.0158 | 0 | 0 | 1.14 KB |
| master | SendReceive |
net472 | 2.14μs | 1.44ns | 5.38ns | 0.183 | 0 | 0 | 1.16 KB |
| #5943 | SendReceive |
net6.0 | 1.39μs | 1.67ns | 6.47ns | 0.016 | 0 | 0 | 1.14 KB |
| #5943 | SendReceive |
netcoreapp3.1 | 1.77μs | 1.83ns | 7.08ns | 0.0151 | 0 | 0 | 1.14 KB |
| #5943 | SendReceive |
net472 | 2.17μs | 1.37ns | 5.13ns | 0.183 | 0 | 0 | 1.16 KB |
Benchmarks.Trace.SerilogBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | EnrichedLog |
net6.0 | 2.79μs | 1.15ns | 4.44ns | 0.0224 | 0 | 0 | 1.6 KB |
| master | EnrichedLog |
netcoreapp3.1 | 3.94μs | 2.01ns | 7.77ns | 0.0218 | 0 | 0 | 1.65 KB |
| master | EnrichedLog |
net472 | 4.35μs | 1.25ns | 4.67ns | 0.322 | 0 | 0 | 2.04 KB |
| #5943 | EnrichedLog |
net6.0 | 2.73μs | 0.9ns | 3.48ns | 0.0217 | 0 | 0 | 1.6 KB |
| #5943 | EnrichedLog |
netcoreapp3.1 | 3.93μs | 1.43ns | 5.56ns | 0.0215 | 0 | 0 | 1.65 KB |
| #5943 | EnrichedLog |
net472 | 4.32μs | 2.56ns | 9.56ns | 0.323 | 0 | 0 | 2.04 KB |
Benchmarks.Trace.SpanBenchmark - Slower ⚠️ Same allocations ✔️
Slower ⚠️ in #5943
Benchmark
diff/base
Base Median (ns)
Diff Median (ns)
Modality
Benchmarks.Trace.SpanBenchmark.StartFinishSpan‑net6.0
1.153
400.60
461.91
Faster 🎉 in #5943
Benchmark
base/diff
Base Median (ns)
Diff Median (ns)
Modality
Benchmarks.Trace.SpanBenchmark.StartFinishScope‑net6.0
1.162
537.55
462.72
| Benchmark | diff/base | Base Median (ns) | Diff Median (ns) | Modality |
|---|---|---|---|---|
| Benchmarks.Trace.SpanBenchmark.StartFinishSpan‑net6.0 | 1.153 | 400.60 | 461.91 |
| Benchmark | base/diff | Base Median (ns) | Diff Median (ns) | Modality |
|---|---|---|---|---|
| Benchmarks.Trace.SpanBenchmark.StartFinishScope‑net6.0 | 1.162 | 537.55 | 462.72 |
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | StartFinishSpan |
net6.0 | 400ns | 0.257ns | 0.993ns | 0.00803 | 0 | 0 | 576 B |
| master | StartFinishSpan |
netcoreapp3.1 | 574ns | 1.16ns | 4.5ns | 0.00761 | 0 | 0 | 576 B |
| master | StartFinishSpan |
net472 | 618ns | 0.706ns | 2.73ns | 0.0916 | 0 | 0 | 578 B |
| master | StartFinishScope |
net6.0 | 537ns | 0.549ns | 2.05ns | 0.00971 | 0 | 0 | 696 B |
| master | StartFinishScope |
netcoreapp3.1 | 685ns | 1.12ns | 4.33ns | 0.00929 | 0 | 0 | 696 B |
| master | StartFinishScope |
net472 | 809ns | 0.641ns | 2.48ns | 0.104 | 0 | 0 | 658 B |
| #5943 | StartFinishSpan |
net6.0 | 462ns | 0.487ns | 1.89ns | 0.00814 | 0 | 0 | 576 B |
| #5943 | StartFinishSpan |
netcoreapp3.1 | 553ns | 0.414ns | 1.6ns | 0.00773 | 0 | 0 | 576 B |
| #5943 | StartFinishSpan |
net472 | 580ns | 0.613ns | 2.38ns | 0.0916 | 0 | 0 | 578 B |
| #5943 | StartFinishScope |
net6.0 | 462ns | 0.323ns | 1.17ns | 0.00974 | 0 | 0 | 696 B |
| #5943 | StartFinishScope |
netcoreapp3.1 | 705ns | 0.567ns | 2.19ns | 0.0091 | 0 | 0 | 696 B |
| #5943 | StartFinishScope |
net472 | 828ns | 1.18ns | 4.58ns | 0.105 | 0 | 0 | 658 B |
Benchmarks.Trace.TraceAnnotationsBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | RunOnMethodBegin |
net6.0 | 582ns | 0.413ns | 1.6ns | 0.00987 | 0 | 0 | 696 B |
| master | RunOnMethodBegin |
netcoreapp3.1 | 899ns | 1.01ns | 3.77ns | 0.00949 | 0 | 0 | 696 B |
| master | RunOnMethodBegin |
net472 | 1.02μs | 1.54ns | 5.96ns | 0.104 | 0 | 0 | 658 B |
| #5943 | RunOnMethodBegin |
net6.0 | 603ns | 0.357ns | 1.38ns | 0.0098 | 0 | 0 | 696 B |
| #5943 | RunOnMethodBegin |
netcoreapp3.1 | 887ns | 1.58ns | 6.11ns | 0.00923 | 0 | 0 | 696 B |
| #5943 | RunOnMethodBegin |
net472 | 1.09μs | 1.96ns | 7.61ns | 0.104 | 0 | 0 | 658 B |
| { | ||
| try | ||
| { | ||
| return request.Headers; |
There was a problem hiding this comment.
I suspect we call this lots of otherplaces too 😕 For example our scope extraction would presumably also trigger this? Do we need to use the helper in that case as well, or is that safe somehow? 🤔
There was a problem hiding this comment.
You don't have this kind of error since 2.54
Taking a close look at the logs, you used to have it in TracingHttpModule.cs, but now you capture all the exceptions.
if (tracer.InternalActiveScope == null)
{
try
{
// extract propagated http headers
headers = httpRequest.Headers.Wrap();
propagatedContext = SpanContextPropagator.Instance.Extract(headers.Value);
}
catch (Exception ex)
{
Log.Error(ex, "Error extracting propagated HTTP headers.");
}
}
I think that in this piece of code, it would be better to use the RequestDataHelper. I will fix it and take a look closer in other places.
There was a problem hiding this comment.
I have made some updates to on the tracinghttpmodule.cs I have not identified other places that use httprequest in net framework where it could happen. The logs also don't show any HttpRequestValidationException out of the already modified classes. I was not sure about AspNetMvcIntegration for instance, but I tried with request after calling ValidateInput and it seems to be fine.
| { | ||
| string path = UriHelpers.GetCleanUriPath(url, app.Request.ApplicationPath); | ||
| scope.Span.ResourceName = $"{app.Request.HttpMethod.ToUpperInvariant()} {path.ToLowerInvariant()}"; | ||
| } |
There was a problem hiding this comment.
I wonder if we should add some resourceName here if we cannot get the url
There was a problem hiding this comment.
Yeah, we probably should - I wonder what we should put though 😕 Unless there's an "unsafe" way we can get the URL so that we can at least include the path, I'm not sure what to do 😅 Worst case we could just use app.Request.HttpMethod.ToUpperInvariant() - is that all we can realistically get?
There was a problem hiding this comment.
I guess that we could use reflection by calling the internal method GetUnvalidatedPath(), but that's pretty ugly and not very efficient. I have updated the code to add the method name.
There was a problem hiding this comment.
GetUnvalidatedPath That actually sounds like the right option to me 😅 We would simply duck-type it and it would work 😉
|
Thanks for the reviews and feedback! |
…rding (#8611) ## Summary of changes - Remove need for allocating a closure - Fix potential `HttpRequestValidationException` leaking in ASM paths ## Reason for change Calling `HttpRequest.Headers` can throw an `HttpRequestValidationException` if the headers contain "dangerous values". We guarded against that in #5943 by adding a helper, but in #6164 we refactored, and stopped using it. ## Implementation details - Reinstates using `RequestDataHelper.GetHeaders()` instead of calling `request.Headers` directly. - Removes the need for a closure allocation every time you call `SecurityCoordinator.ExtractHeaders()` by allowing you to pass the collection in to the method, and passing that through to the `Func`. Not required, just a minor perf optimization ## Test coverage Meh - correctness should be covered by existing tests. Adding a regression test seems overkill tbh
Summary of changes
We are logging some not handled HttpRequestValidationException errors
In the past, we protected the reading of the query string to avoid such issues, but now they seem to be caused by the values of headers and cookies.
This error occurs in .Net framework. If the method request.ValidateInput is called, the request will launch an exception if the cookies, url or header values are dangerous.
In the past, we created a class called QueryStringValidator. In this PR, the features of this class are extended to cookies and headers and urls. The class has been renamed to RequestDataValidator.
Reason for change
Implementation details
Test coverage
Some unit tests have been added.
Other details