String Fields Right Boundary
| Item | Description |
|---|---|
| Full Fuzzer Name | StringFieldsRightBoundaryFuzzer |
| Log Key | SFRB |
| Description | This fuzzer will send right boundary values in string fields. The expectation is that APIs will reject the request as invalid, as the value is larger than the maxLength. |
| Enabled by default? | Yes |
| Target field types | OpenAPI type string |
| Expected result when fuzzed field is required | 4XX |
| Expected result when fuzzed field is optional | 4XX |
| Expected result when fuzzed value is not matching field pattern | 4XX |
| Fuzzing logic | Iteratively replaces string fields with right boundary values: if the field has a defined maxLength the fuzzer will generate an alphanumeric string of length maxLength + 10; if maxLength > 2147483647 then maxLength will be considered 2147483645. If the field does not have a maxLength is will generate a string of length 10000. |
| Conditions when this fuzzer will be skipped | When field is not of type string |
| HTTP methods that will be skipped | None |
| Reporting | Reports error if: 1. response code is 404; 2. response code is documented, but not expected; 3. any unexpected exception. Reports warn if: 1. response code is expected and documented, but not matches response schema; 2. response code is expected, but not documented; 3. response code is 501. Reports success if: 1. response code is expected, documented and matches response schema. |