Commit b1ffeb4
authored
[ANCHOR-1185] Add XDR size validation in SEP-10 and SEP-45 auth endpoint (#1917)
### Description
- Add 50KB size limit on `transaction` field in SEP-10 POST `/auth`
before XDR parsing
- Reduce existing SEP-45 `authorization_entries` size limit from 100KB
to 50KB
### Context
Valid SEP-10/SEP-45 auth payloads are small (a few KB). Limiting input
size before XDR deserialization prevents unnecessary memory allocation
from oversized payloads.
### Testing
- `./gradlew test`
### Documentation
N/A
### Known limitations
N/A1 parent f4d63f9 commit b1ffeb4
4 files changed
Lines changed: 24 additions & 2 deletions
File tree
- core/src
- main/java/org/stellar/anchor
- sep10
- sep45
- test/kotlin/org/stellar/anchor
- sep10
- sep45
Lines changed: 5 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
511 | 511 | | |
512 | 512 | | |
513 | 513 | | |
514 | | - | |
| 514 | + | |
515 | 515 | | |
516 | 516 | | |
517 | 517 | | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
| 521 | + | |
518 | 522 | | |
519 | 523 | | |
520 | 524 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
180 | 180 | | |
181 | 181 | | |
182 | 182 | | |
183 | | - | |
| 183 | + | |
184 | 184 | | |
185 | 185 | | |
186 | 186 | | |
| |||
Lines changed: 8 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
280 | 280 | | |
281 | 281 | | |
282 | 282 | | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
283 | 291 | | |
284 | 292 | | |
285 | 293 | | |
| |||
Lines changed: 10 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
192 | 192 | | |
193 | 193 | | |
194 | 194 | | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
195 | 205 | | |
196 | 206 | | |
197 | 207 | | |
| |||
0 commit comments