Under Posting Attack in .NET Core

net 6 newbie 121 Reputation points

In .NET 6 I have a DTO with value data types like int.

But while sending a POST request if user omits the value for that default value is getting assigned without any Error.

What are the best practices to avoid this under posting?

I have tried using [Required] ,[BindRequired] but still not addressed my concern.

I know we can add some other validation attribute to check if value is not equal to 0. But I want to know how to validate the under posting attack.

A set of technologies in the .NET Framework for building web applications and XML web services.
4,238 questions
{count} votes

1 answer

Sort by: Most helpful
  1. AgaveJoe 26,166 Reputation points

    Use a nullable int type and check for null.

        public class MyClass
            public int? MyNullableInt { get; set; }

    The official documentation covers model validation.


    0 comments No comments