Request body parsing differences
Compare how the edge and application handle a documented request when its body is valid, malformed, duplicated, or sent with an alternate supported media type. Use only harmless fields and owned records.
Tags: http, parsing, api, authorized-testing
Techniques
Content type agreement
Check whether a route consistently rejects a body whose declared type does not match its syntax; inconsistencies can expose validation gaps.
Content-Type: application/json with a minimal valid JSON test bodyContent-Type: application/x-www-form-urlencoded with the same benign field
Duplicate field policy
Use distinct non-sensitive markers to learn whether the parser accepts first, last, arrays, or rejects duplicates.
role_hint=CANARY-A&role_hint=CANARY-B{"note":"CANARY-A","note":"CANARY-B"}
Boundary behavior
For upload or multipart endpoints, compare ordinary form fields and an empty, permitted file field; do not submit oversized data or unsafe file content.
multipart/form-data with a small text fieldempty optional file field with a benign .txt fixture