Skip to content

Parameters too loose on API calls #825

@pscott

Description

@pscott

Description

You can pass some extra useless parameters to some API calls.

Present Behaviour

A number of API calls allow for useless parameters to be passed in. For example /beacon/head doesn't check for any parameters, so you can call /beacon/head?slot=0.

I don't think this presents any security issues.
However, from a user perspective, it could be confusing.

Expected Behaviour

One would expect this to return an error.

Steps to resolve

Check that API calls do not allow for extra useless parameters to be passed in.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions