RESTful Service and Validation

I am new to using RESTful Service and not sure how to validate the input passed to the methods to avoid various security vulnerabilities. Any pointer appreciated.

Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Alexandre SimõesManager / Technology SpecialistCommented:
Hi mate.
Being a RESTful service shouldn't affect the way you validate user input.
It really all depends on what each method receives and does with the input.

To avoid SQL Injection for instance, the rule is always the same, doesn't matter where you use it: Never generate SQL queries based on string concatenation with user input.

So, as far as user input is concern, don't think about a REST service as something different of a webform save method or anything else that handles user input.
JRR75Author Commented:
Let me put my question this way, how to validate the JSON passed to the web method?
Alexandre SimõesManager / Technology SpecialistCommented:
The request won't arrive in the method as json anyway.
On the service side you'll have a normal function with normal typed arguments.
The service will do the parsing job for you automatically mapping the JSON object properties to your method arguments.
You just have to make sure the names are exactly the same.
{ userId: 200 }

Open in new window

will map to
public void GetUser(int userId){ // your code }

Open in new window


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.