RERUM Can Be Attacked By Trees
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 48/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 冷清
- 技术栈
- javascript
调研方向
先定位 getAllVersions 的实现和内部版本查询路径,然后将它们的行为与 issue 中描述的 /query 分页方式进行比较。部署应用,并测试具有 100 个版本和 1000 多个版本的对象;当响应数量上限为 100、游标能够获取剩余版本,并且版本很多的对象不再耗尽 pm2 内存时,即表示完成。
由索引模型根据 Issue 内容生成。
描述
getAllVersions loads unbounded data into memory. We were able to perform a successful History Tree Attack using an object that has 100 versions in history. Deeply versioned objects (1000+) can cause pm2 threads to run out of memory.
Recommendation: Add pagination to version queries. Limit default response to 100 versions with cursor-based pagination. This is how using /query for large data responses is handled by clients when they query for data. The technique can be used internally too.
Ensure the change is functional by testing it yourself and ensuring it solves the attack vector. Human developers can deploy the app and manually test the code you propose.
- 主要语言
- JavaScript
- 星标
- 3
- 派生
- 6
- 平均合并
- 4 天 9 小时
- 30 天内合并 PR
- 5
环境准备
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
CenterForDigitalHumanities/rerum_server_nodejs 的其他 Issue
-
bug documentation
难度 2/5 1-3 小时 新手友好度 88/100
-
backend dependencies easy
难度 2/5 1-3 小时 新手友好度 84/100
-
难度 2/5 1-3 小时 新手友好度 82/100
CenterForDigitalHumanities/rerum_server_nodejs#290 · 1 条评论 ·
-
难度 4/5 3-5 天 新手友好度 50/100
-
难度 3/5 1-2 天 新手友好度 74/100
查看 CenterForDigitalHumanities/rerum_server_nodejs 的全部 Issue
相似的 Issue
-
factory-active factory-automatic harness/codex task-bug-reproduction-success task-identify-harness-labels-done task-identify-issue-type-done
难度 2/5 1-3 小时 新手友好度 85/100
维护者通常 1 天内回复
-
ux
难度 1/5 1 小时以内 新手友好度 90/100
rr-djk/rr-djuikoo.com#53 ·
维护者通常 1 天内回复
-
new spec review
难度 2/5 1-3 小时 新手友好度 72/100
w3c/browser-specs#2666 · 1 条评论 ·
维护者通常 3 天内回复
-
难度 2/5 1-3 小时 新手友好度 76/100
thim81/openapi-format#238 ·
-
难度 2/5 1-3 小时 新手友好度 82/100
decentespresso/dye2#13 ·