Skip to content

fix: add maxLength constraints to unbounded TypeBox string schemas - #373

Merged
birme merged 1 commit into
mainfrom
security-audit/fix-239-maxlength-typebox
Sep 25, 2026
Merged

birme merged 1 commit into
mainfrom
security-audit/fix-239-maxlength-typebox

Conversation

@birme

@birme birme commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds maxLength constraints to input TypeBox string schemas that were previously unbounded, so Fastify/AJV rejects oversized payloads with a 400 (defence-in-depth against memory exhaustion, slow queries, and oversized log entries). Closes #239.

Values follow the business-rule guidance in the issue:

  • IDs / short identifiers → maxLength: 128
  • Human-readable names / labels → maxLength: 200
  • SDP offer blob → maxLength: 65536 (mirrors the existing SdpAnswer.sdpAnswer bound)

Response-only schemas were intentionally left unbounded (no input-hardening benefit; bounding outputs risks breaking legitimate serialization). Existing minLength/format/pattern constraints are preserved — only maxLength was added.

Touched: src/models.ts, src/api_productions.ts, src/api_ingests.ts, src/api_groups.ts, plus tests in src/api_validation.test.ts.

Note: route params hit Fastify's default maxParamLength (100 → 414) before the added 128 bound, so param-level bounds are redundant-but-harmless; the body-field bounds are the ones that produce 400s.

Test plan

  • npm run lint — pass (no new warnings)
  • npm run typecheck — pass
  • npm test — pass (18 suites, 349 tests; +6 new tests covering oversized rejection and valid pass-through for a param, session body, and ingest body)
  • prettier --check on edited files — clean

Closes #239

🤖 Generated with Claude Code

Add defence-in-depth maxLength bounds to previously unbounded
Type.String() schemas on request inputs (route params and body
fields) so Fastify/AJV rejects oversized payloads with 400 before
they reach handlers.

- IDs (productionId, ingestId, preset id, PresetCall ids): 128
- Names/labels (Line/Production name, ingest label/device names,
  lineName): 200
- SDP offer (WhipWhepRequest): 65536 to match the existing SdpAnswer
  bound

Extend api_validation tests to cover oversized rejection and valid
values for representative fields.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@birme

birme commented Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

Independent code-reviewer verdict: LGTM. Full input-field coverage verified (including Type.Omit-inherited PATCH bodies), no bound too tight for realistic input, meaningful body-field boundary tests, style adherent. Only non-blocking nits (param-level 128 bound is unreachable behind Fastify's maxParamLength=100, one weak param test, a lineId 128/200 inconsistency) — none blocking. Posted as a marker rather than a GitHub review because self-authored PRs cannot carry a state-bearing review.

@birme
birme merged commit af5c693 into main Sep 25, 2026
4 checks passed
@birme
birme deleted the security-audit/fix-239-maxlength-typebox branch September 25, 2026 09:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security: Add maxLength constraints to unbounded TypeBox String schemas

2 participants