Doichain/dapp

Security: RPC-API-CALL sendrawtransaction needs validation

开放

#116 创建于 2019年10月29日

 (1 条评论) (0 个反应) (0 位负责人)JavaScript (13 个派生)auto 404
A prioritybountyenhancementgood first issuehelp wantedsecurity

仓库指标

星标
 (6 个星标)
PR 合并指标
 (PR 指标待抓取)

描述

When calling RPC-API sendrawtransaction please validate and limit the data given over the body parameters to prevent dDoS attacks.

This RPC-Call is located in: meteor-api package: https://github.com/Doichain/meteor-api inside file: server/api/rest/imports/send.js around line 639: Api.addRoute(DOICHAIN_BROADCAST_TX, { parameter*: !params.templateDataEncrypted || ... etc. is not yet limited. The size of this parameter (size of data) should be able to be limited in settings

The question here is if restivus (the REST API package of meteor) already has such capabilities or we must do it AFTER we received 1 GB of data. I think this could be already too late here.

贡献者指南