Lukasz Lenart created WW-5666:
---------------------------------

             Summary: Apply input length limits consistently when reading 
request bodies
                 Key: WW-5666
                 URL: https://issues.apache.org/jira/browse/WW-5666
             Project: Struts 2
          Issue Type: Improvement
            Reporter: Lukasz Lenart
             Fix For: 7.3.0


h2. Summary

Two request-body reading paths apply input limits less consistently than the 
rest of the framework. This issue makes the JSON input length limit apply 
uniformly while reading, and gives the CSP reporting path a configurable limit 
of its own.

h2. Current behaviour

*JSON plugin*

{{JSONUtil.deserializeInput(Reader, int)}} accumulates input a line at a time 
and compares the accumulated length against {{struts.json.maxLength}} between 
lines. The limit is therefore applied after input has been accumulated rather 
than while it is being read, which makes enforcement less predictable than the 
other configured limits in the plugin ({{struts.json.maxDepth}}, 
{{struts.json.maxElements}}, {{struts.json.maxStringLength}}, 
{{struts.json.maxKeyLength}}).

*CSP reporting*

{{CspReportAction}} reads the submitted report body with a single 
{{readLine()}} call and has no limit of its own. Unlike the JSON path, there is 
no way for an application to declare how large a report it is prepared to 
accept, and no limit is applied by default.

h2. Proposed change

* Evaluate the JSON input length limit as input is read, in fixed-size chunks, 
so that enforcement does not vary with the structure of the input.
* Read the CSP report body up to a limit, defaulting to 8192 characters, 
exposed as a {{maxReportSize}} property on {{CspReportAction}} so applications 
can tune it. A report above the limit is discarded with a warning rather than 
processed.

h2. Compatibility notes

*JSON plugin*

* Line terminators are no longer stripped while reading. They are insignificant 
whitespace between tokens, so parsing is unaffected.
* An unescaped control character appearing inside a JSON string value is now 
preserved in the parsed value rather than silently removed. Such input is not 
valid JSON; applications relying on the previous silent removal may observe 
different values.

*CSP reporting*

* {{processReport}} now receives the whole body up to the limit rather than 
only its first line.
* An empty body is passed as an empty string rather than {{null}}.

h2. Notes

{{JSONUtil}} is already marked for removal in 8.0.0 under WW-5619. This change 
targets the existing class and does not affect that plan.




--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to