Skip to content

Conversation

maheshkukreja
Copy link
Contributor

This PR fixes issue #1716.

As a follow up, we'll need to clean up the HTML5 Security Cheat Sheet to remove websocket related text in there.

@randomstuff
Copy link

I don't have much data to back it up but I would think that memory(/resource) exhaustion caused by the lack of control flow/backpressure support in many WebSocket implementations may an important security considerations to add in there?

@maheshkukreja
Copy link
Contributor Author

I don't have much data to back it up but I would think that memory(/resource) exhaustion caused by the lack of control flow/backpressure support in many WebSocket implementations may an important security considerations to add in there?

Thanks for the feedback, @randomstuff - I think I addressed your concerns, let me know if there's anything else.

@jmanico
Copy link
Member

jmanico commented Sep 5, 2025

As a follow up, we'll need to clean up the HTML5 Security Cheat Sheet to remove websocket related text in there.

Can you kindly submit this as a separate issue?

Copy link
Member

@jmanico jmanico left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have some suggestion to add to this, but nothing is wrong and its a great start.

@maheshkukreja
Copy link
Contributor Author

As a follow up, we'll need to clean up the HTML5 Security Cheat Sheet to remove websocket related text in there.

Can you kindly submit this as a separate issue?

#1783

Copy link
Collaborator

@mackowski mackowski left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Awesome work! Thanks @maheshkukreja

@mackowski mackowski merged commit 60e0f6b into OWASP:master Sep 8, 2025
3 checks passed
@maheshkukreja maheshkukreja deleted the maheshkukreja-websocket-security-cheatsheet branch September 8, 2025 17:35
Prasad-JB pushed a commit to Prasad-JB/CheatSheetSeries that referenced this pull request Sep 8, 2025
* add WebSocket_Security_Cheat_Sheet.md

* address randomstuff's comments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants