मुख्य सामग्री पर जाएँ

SaaS apps में LLM output handling सुरक्षा

Contextual encoding, strict schemas, server-side validation और tests से AI output के कारण XSS, SQL injection, SSRF या unsafe actions रोकें।

इस मार्गदर्शिका में

SaaS app को LLM output सुरक्षित तरीके से कैसे handle करना चाहिए?

हर model response को untrusted input मानें, भले वह system prompt के अनुसार हो या valid JSON जैसा दिखे। खतरा अक्सर अगले component में पैदा होता है: browser renderer, database query, shell command, URL fetch, email template या workflow action। Receiving boundary पर intended meaning validate करें, सही context के अनुसार encode करें और authorization trusted application code में रखें।

Model text को contextual encoding और safe Markdown से render करें

Plain text को framework के text rendering से दिखाएं। Markdown या rich text समर्थित हो तो maintained renderer इस्तेमाल करें जिसमें raw HTML बंद हो या संकीर्ण allowlist से sanitize हो। Links और attributes encode करें, scriptable URL schemes रोकें, और SVG, HTML, event-handler, nested encoding तथा bidirectional text के cases जांचें। Content Security Policy impact घटा सकती है, unsafe rendering को सुरक्षित नहीं बनाती।

Structured output को syntax और business rules से validate करें

Trusted parser से JSON पढ़ें, strict schema लागू करें, unknown fields अस्वीकार करें और strings, arrays तथा numbers की सीमा रखें। फिर business meaning जांचें: tenant IDs, अनुमत status, currency, destinations और state transitions authenticated request के लिए वैध हों। Schema shape सिद्ध करता है, truth, authority या safety नहीं।

इस बिंदु के स्रोत: LLM05:2025 Improper Output HandlingOWASP Cheat Sheet: authorization

Generated text को executable interpreters से दूर रखें

Model text को SQL, shell commands, templates, HTML या policy expressions में जोड़कर कभी न चलाएं। Parameterized database queries, fixed server-side operations और allowlisted arguments इस्तेमाल करें। LLM-generated URL को SSRF defenses, destination checks और network egress controls के बिना server request न बनाएं; generic command या query tools से बचें।

Model output destination समीक्षा
Output destinationParser या encoderSemantic/authorization checksFailure behaviorMalicious-output test
Browser answer या Markdown
Database या workflow update
URL fetch या बाहरी message

Unsafe downstream actions को कैसे रोकें?

Generated instructions चलाने के बजाय server-owned actions इस्तेमाल करें

Validated response को छोटे typed business operations से map करें। Server operation चुने, मौजूदा records authorized tenant के भीतर लोड करे और user की permissions लागू करे। Implementation आसान बनाने के लिए generated SQL, code, shell text, browser scripts या unrestricted API requests न चलाएं।

दिखाने से पहले citations, links और claims validate करें

Feature citations दिखाए तो सुनिश्चित करें कि हर reference उसी source पर जाए जिसे user access कर सकता है और citation retrieved passage या stored record से जुड़ा हो। Model text से URL बनाकर उसे सुरक्षित न मानें। High-impact advice के साथ बताएं कि output generated है और underlying source verify करने या human review पाने का रास्ता दें।

Malformed या अधूरे response पर सुरक्षित रूप से रुकें

Timeout और size limits रखें, streaming chunks render करने से पहले validate करें, और refusal, truncation, provider errors तथा schema mismatch स्पष्ट रूप से handle करें। Payment, access change, deletion या बाहरी delivery में missing value का अनुमान न लगाएं और अनिश्चित side effect blindly retry न करें; reviewed recovery step पर भेजें।

कौन से tests LLM output handling की कमजोरी पकड़ते हैं?

Browser output और Markdown rendering को fuzz करें

Feature को HTML tags, event handlers, javascript जैसे links, data URLs, malformed Markdown, nested encodings और लंबे Unicode strings दें। जांचें कि rendered DOM inert text या स्वीकृत elements ही रखे और links तय policy से बाहर न जाएं। Saved और streamed model response render करने वाले हर component में test दोहराएं।

Parsers, databases और network integrations जांचें

JSON में अतिरिक्त fields, गलत types, बहुत बड़ी values, SQL-जैसी strings, shell metacharacters, private IP addresses, redirects और अनपेक्षित URL schemes test करें। पुष्टि करें कि parameterized queries strings को data ही रखें, outbound network controls निषिद्ध destinations रोकें और invalid values से partial side effect न हो।

Output के आसपास tenant authorization और logging जांचें

Model से दूसरे tenant का identifier, privileged role, unauthorized citation या छिपे record reference निकलवाने की कोशिश करें। Output सही format में हो तब भी server उसे reject करे। पुष्टि करें कि logs पूरा prompt या private generated text अपने-आप store किए बिना policy outcome और output version दर्ज करते हैं।

LLM output security: अक्सर पूछे जाने वाले सवाल

क्या model का valid JSON इस्तेमाल करना सुरक्षित है?

नहीं। JSON parsing और schema validation structure बचाते हैं, पर action से पहले application code को values, ownership, permissions और अनुमत state transitions भी जांचने होंगे।

इस बिंदु के स्रोत: LLM05:2025 Improper Output HandlingOWASP Cheat Sheet: authorization

क्या React model-generated पूरा text सुरक्षित रूप से render करता है?

Plain text को text की तरह render करना HTML inject करने से सुरक्षित है, लेकिन rich-text libraries, raw HTML, URL links और अन्य sinks की अपनी validation और encoding चाहिए। जिस renderer और configuration का उपयोग हो, उसी को test करें।

क्या LLM SQL बनाए तो उसे सावधानी से चलाया जा सकता है?

Customer data पर generated SQL execute न करें। Fixed application operations और parameterized queries चुनें। अगर product में सीमित analytics language हो तो उसे allowlisted query plan में parse करें और tenant scope अलग से लागू करें।

क्या content moderation filter output को सुरक्षित बना देता है?

नहीं। कोई एक filter XSS, SSRF, injection, unauthorized data और business-rule failures सभी नहीं रोकता। हर downstream boundary पर output validate करें और model को जरूरत से ज्यादा authority न दें।

इस बिंदु के स्रोत: LLM05:2025 Improper Output HandlingLLM06:2025 Excessive Agency