PHPerKaigi 2024 ⢠Day 1ã§ã®ç»å£è³æã§ãã https://phperkaigi.jp/2024/ https://fortee.jp/phperkaigi-2024/proposal/0d0f8507-0a53-46f6-bca6-23386d78f17f â» Authorâ¦
ãã®è¨äºã®ç®ç ä»ã¾ã§ Web ã¢ããªã±ã¼ã·ã§ã³è£½ä½ãè¡ã£ãçµé¨ãç¡ãæ¹ããã¡ãã£ã¨å人éçºã§ä½ãä½ã£ã¦ã¿ããããªï¼ãã¨æã£ãã¨ãã«ãã£ããèå¼±æ§ãä½ãããã§ãã¾ããã¨ãå°ãã§ãé²ããããããªã¨èãã¾ããã ãã®ããã«ã¯ã¾ãèå¼±æ§ãä»äººäºã ã¨èããªããã¨ã大äºã ã¨æã£ãã®ã§ãç§ãéå»ã®éçºç¾å ´ã«ããã¦å®éã«ééãããã¨ããã Web ã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ã®äºä¾ãå¹¾ã¤ãç´¹ä»ãã¾ãã ç´¹ä»ã®åã«æ³¨æåèµ·ããã¾ãã èªåã管çãã¦ããããã§ã¯ãªã Web ã¢ããªã±ã¼ã·ã§ã³ã«å¯¾ããä¾é ¼ããã¦ãããªãã®ã«èå¼±æ§ãæ¢ãè¡çºã¯çµ¶å¯¾ã«ããªãã§ãã ããããã®è¡çºã®å 容ã«ãã£ã¦ã¯ç¯ç½ªã«ãªãå¯è½æ§ãããã¾ãã å¤é¨ãã渡ããããã¼ã¿ãä½ã®å¯¾çããªãã« SQL ã«åãè¾¼ãã§ãã SQL ã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æã®èª¬æã§ããã¿ãããä¾ã§ããããã°ã¤ã³å¦çã§ã¦ã¼ã¶ã¼ãå ¥åãã ID ã¨ãã¹ã¯ã¼ãã«ä¸è´ããã¦ã¼ã¶ã¼æ å ±
è¦ã¦ãããµã¤ãä¸ã«é²åºãã¦ããæ©å¯æ å ±(APIãã¼ã¯ã³ãIPã¢ãã¬ã¹ãªã©)ãè¦ã¤ãããã©ã¦ã¶æ¡å¼µãä½ãã¾ãã Secretlintã¨ããAPIãã¼ã¯ã³ãªã©ã®æ©å¯æ å ±ããã¡ã¤ã«å ã«å«ã¾ãã¦ãããããã§ãã¯ã§ãããã¼ã«ãæ¸ãã¦ãã¾ãã Secretlintã¯ã³ãã³ãã©ã¤ã³ãã¼ã«ã¨ãã¦åãã®ã§ã主ã«CIãGitã®pre-commit hookãå©ç¨ãã¦ããªãã¸ããªã«æ©å¯æ å ±ãå ¥ãã®ãé²æ¢ã§ãã¾ãã Secretlintã§APIãã¼ã¯ã³ãç§å¯éµãªã©ã®ã³ããããé²æ¢ãã | Web Scratch ä¸æ¹ã§ãå®éã®ã¦ã§ããµã¼ãã¹ãªã©ã¯æ©å¯æ å ±ããã¡ã¤ã«ã«ãã¼ãã³ã¼ãããã¦ããããã§ã¯ãªã(Secrelintèªä½ããããããã¼ãã³ã¼ããé²ããã¼ã«ã§ã)ãç°å¢å¤æ°ãDatabaseã«ä¿åãã¦ããã¨æãã¾ãã ãã®ãããªå ´åã«ããã³ã¼ãã®ãã¹ãªã©ã«ãã£ã¦å ¬éããã¹ãã§ã¯ãªãæ å ±(ç§å¯éµãAPIãã¼ã¯ã³ãSl
note ã®ããããã®ãã®ã¸ãã«ã¤ãã¦ã èªè¨¼èªä½ã Rails ã Devise - Diary ãã¼ãã§ã¯ã Rails èè ã解説ãã devise ã®ç¾ä»£çãªã¦ã¼ã¶ã¼èªè¨¼ã®ã¢ãã«æ§æã«ã¤ã㦠- joker1007âs diary èªè¨¼ãµã¼ãã¼ã®å®è£ ã¯æ¬è³ªçã«é£ããã§ããã»ãã¥ãªãã£ã絡ããã®ã¯ãç°¡åãªå®è£ ããªã©ãªããããã¢ãå人æ³äººåãããå人æ å ±ãå®ãã¨ããç¹ã§ãåãæ°´æºãè¦æ±ããã¾ããæªæããããã«ã¼ã¯å¸¸ã«ã«ã¢ãæ¢ãã¦ãã¦ãããèªè¨¼ãç ´ãããå ´åãèªåã ãã§ã¯ãªã大å¤æ°ã«è¿·æãæããã¾ããåå¿è ã ããå 責ãããã¨ãã£ããã¨ãããã¾ãããå ¨å¡ãåãå俵ã«ç«ãããã¦ãã¾ãã ã¨ã¯ãããèªè¨¼åºç¤ãä½ããªãã¨ããããªãµã¼ãã¹ãæç«ãã¾ãããããããã¨ãã«ã©ããããã Firebase Authentication ã§ãã¿ã¤ãã«ã®ä»¶ãªãã§ããã Firebase Authenticat
WEBç³»ã®æ å ±ã»ãã¥ãªãã£é¢é£ã®å¦ç¿ã¡ã¢ã§ããã¡ã¢ãªã®ã§ä»æ å ±ã®ãã¤ã³ã¿ã ããã¨ãã®åæ¯ãªè¨äºãããã¾ãã â»2020.9 注è¨:æ¬ããã°ã®è§£èª¬è¨äºã¯å 容ãå¤ããªã£ã¦ããã¾ããOWASP ZAPãªã©ã®ã½ããã¦ã§ã¢ã®è§£èª¬ã¯ç¾è¡ãã¼ã¸ã§ã³ã®ä»æ§ããä¹é¢ãã¦ããå¯è½æ§ãããã¾ãã EC-CUBEã§èå¼±æ§ãè¦ã¤ããããmixiã®èå¼±æ§å ±åå¶åº¦ã§ææãæããããããããããã©ããã£ã¦èå¼±æ§ãè¦ã¤ãã¦ããã§ããï¼ãã¨ãã質åãããããã¨ãææãããä¸å¿æé ã¯èª¬æããã®ã§ããããã¤ãå£é ã§ç´°ããã¯èª¬æã§ããªãã¦ç³ã訳ãªãã®ã§ãèªåã®ããæ¹ãã¾ã¨ãã¦ãã®ããã°ã«ã¢ãããã¦ããã¾ãã æ¨æºçãªèå¼±æ§æ¤æ»ã®ããæ¹ãã説æãã¦ããªãã®ã§ãèå¼±æ§æ¤æ»ã®ããæ¹ãæ¢ã«ææ¡ãã¦ãã人ãèªãã§ãå¾ããã®ã¯å°ãªãã®ã§ã¯ãªããã¨æãã¾ããä»åã¯èå¼±æ§æ¤æ»ã«èå³ããããä½ãã©ãããããããåãããªããããªåå¿è åãã³ã³ãã³ãã§
èå¼±æ§ä½é¨å¦ç¿ãã¼ã« AppGoat èå¼±æ§ä½é¨å¦ç¿ãã¼ã« AppGoatã¨ã¯ èå¼±æ§ä½é¨å¦ç¿ãã¼ã«ãAppGoatãã¯ãèå¼±æ§ã®æ¦è¦ã対çæ¹æ³çã®èå¼±æ§ã«é¢ããåºç¤çãªç¥èãå®ç¿å½¢å¼ã§ä½ç³»çã«å¦ã¹ããã¼ã«ã§ããå©ç¨è ã¯ãå¦ç¿ãã¼ãæ¯ã«ç¨æãããæ¼ç¿åé¡ã«å¯¾ãã¦ãåãè¾¼ã¾ããèå¼±æ§ã®çºè¦ãããã°ã©ãã³ã°ä¸ã®åé¡ç¹ã®ææ¡ã対çææ³ã®å¦ç¿ã対話çã«å®æ½ã§ãã¾ãã ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§å¯¾çã«å¿ è¦ãªã¹ãã«ãç¿å¾ãããéçºè ãã¦ã§ããµã¤ãã®ç®¡çè ã«ããããã§ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}