Skip to content

Use DefaultBodyLimit to prevent json request parsing DDoS #322

@gtema

Description

@gtema

AI identified a potential for the DDoS in JSON request parsing. While axum already implements body limits it makes sense to document this explicitly and provide operator with configuration options to fine-tune this.
https://docs.rs/axum/latest/axum/extract/struct.DefaultBodyLimit.html
It must be noted that the python Keystone is also "vulnerable" to this attack due to the lack of explicit documentation.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    Status

    Done

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions