Skip to content

fix: cap invite_user list at 20 - #1636

Open
TastyHeadphones wants to merge 1 commit into
apache:mainfrom
TastyHeadphones:fix/cap-invite-user-list
Open

TastyHeadphones wants to merge 1 commit into
apache:mainfrom
TastyHeadphones:fix/cap-invite-user-list

Conversation

@TastyHeadphones

Copy link
Copy Markdown

PUT /answer/api/v1/question/invite took an uncapped invite_user array, so one request could trigger a huge notification fan-out. ASF security called that out as hardening rather than a boundary issue.

Added max=20 on the request structs (validator) and the same limit in the invite UI when picking people.

Fixes #1617

The invite endpoint accepted an uncapped invite_user array, so one
request could fan out a huge number of notifications. Match a 20-user
server/UI limit.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Hardening: cap the invite_user list size in UpdateQuestionInviteUser to bound notification fan-out

1 participant