Bound JSON-RPC input by size and nesting depth

Enforce the nesting bound in one parse, capping allocation by depth, not input size.
This commit is contained in:
xirvik
2026-09-19 02:11:20 +00:00
committed by Jari Sundell
parent 83b03c2c1e
commit 439d23ce62
5 changed files with 130 additions and 1 deletions
+7
View File
@@ -5,6 +5,8 @@
#include <cstdint>
#include "rpc/scgi_task.h"
namespace rpc {
class JsonRpc {
@@ -17,6 +19,11 @@ public:
bool process(const char* in_buffer, uint32_t length, slot_write callback);
void insert_command(const char* name, const char* parm, const char* doc) {};
void set_size_limit(uint64_t size) { m_size_limit = size; }
private:
uint64_t m_size_limit{SCgiTask::max_content_size};
};
} // namespace rpc