fix: add maxLength constraints to unbounded TypeBox string schemas - #373
Merged
Merged
Conversation
Add defence-in-depth maxLength bounds to previously unbounded Type.String() schemas on request inputs (route params and body fields) so Fastify/AJV rejects oversized payloads with 400 before they reach handlers. - IDs (productionId, ingestId, preset id, PresetCall ids): 128 - Names/labels (Line/Production name, ingest label/device names, lineName): 200 - SDP offer (WhipWhepRequest): 65536 to match the existing SdpAnswer bound Extend api_validation tests to cover oversized rejection and valid values for representative fields. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Contributor
Author
|
Independent code-reviewer verdict: LGTM. Full input-field coverage verified (including |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
maxLengthconstraints to input TypeBox string schemas that were previously unbounded, so Fastify/AJV rejects oversized payloads with a 400 (defence-in-depth against memory exhaustion, slow queries, and oversized log entries). Closes #239.Values follow the business-rule guidance in the issue:
maxLength: 128maxLength: 200maxLength: 65536(mirrors the existingSdpAnswer.sdpAnswerbound)Response-only schemas were intentionally left unbounded (no input-hardening benefit; bounding outputs risks breaking legitimate serialization). Existing
minLength/format/patternconstraints are preserved — onlymaxLengthwas added.Touched:
src/models.ts,src/api_productions.ts,src/api_ingests.ts,src/api_groups.ts, plus tests insrc/api_validation.test.ts.Note: route params hit Fastify's default
maxParamLength(100 → 414) before the added 128 bound, so param-level bounds are redundant-but-harmless; the body-field bounds are the ones that produce 400s.Test plan
npm run lint— pass (no new warnings)npm run typecheck— passnpm test— pass (18 suites, 349 tests; +6 new tests covering oversized rejection and valid pass-through for a param, session body, and ingest body)prettier --checkon edited files — cleanCloses #239
🤖 Generated with Claude Code