mirror of
https://github.com/json-iterator/go.git
synced 2025-04-26 11:42:56 +02:00
Merge pull request #418 from bbrks/configurable_maxDepth
Add MaxDepth as a config option
This commit is contained in:
commit
44a7e7340d
@ -2,9 +2,11 @@ package test
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
"github.com/json-iterator/go"
|
jsoniter "github.com/json-iterator/go"
|
||||||
"github.com/stretchr/testify/require"
|
"github.com/stretchr/testify/require"
|
||||||
)
|
)
|
||||||
|
|
||||||
@ -24,6 +26,44 @@ func Test_customize_float_marshal(t *testing.T) {
|
|||||||
should.Equal("1.234568", str)
|
should.Equal("1.234568", str)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func Test_max_depth(t *testing.T) {
|
||||||
|
deepJSON := func(depth int) []byte {
|
||||||
|
return []byte(strings.Repeat(`[`, depth) + strings.Repeat(`]`, depth))
|
||||||
|
}
|
||||||
|
|
||||||
|
tests := []struct {
|
||||||
|
jsonDepth int
|
||||||
|
cfgMaxDepth int
|
||||||
|
expectedErr string
|
||||||
|
}{
|
||||||
|
// Test the default depth
|
||||||
|
{jsonDepth: 10000, cfgMaxDepth: 0},
|
||||||
|
{jsonDepth: 10001, cfgMaxDepth: 0, expectedErr: "max depth"},
|
||||||
|
// Test max depth logic
|
||||||
|
{jsonDepth: 5, cfgMaxDepth: 6},
|
||||||
|
{jsonDepth: 5, cfgMaxDepth: 5},
|
||||||
|
{jsonDepth: 5, cfgMaxDepth: 4, expectedErr: "max depth"},
|
||||||
|
// Try a large depth without a limit
|
||||||
|
{jsonDepth: 128000, cfgMaxDepth: -1},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, test := range tests {
|
||||||
|
t.Run(fmt.Sprintf("jsonDepth:%v_cfgMaxDepth:%v", test.jsonDepth, test.cfgMaxDepth), func(t *testing.T) {
|
||||||
|
should := require.New(t)
|
||||||
|
cfg := jsoniter.Config{MaxDepth: test.cfgMaxDepth}.Froze()
|
||||||
|
|
||||||
|
var val interface{}
|
||||||
|
err := cfg.Unmarshal(deepJSON(test.jsonDepth), &val)
|
||||||
|
if test.expectedErr != "" {
|
||||||
|
should.Error(err)
|
||||||
|
should.Contains(err.Error(), test.expectedErr)
|
||||||
|
} else {
|
||||||
|
should.NoError(err)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func Test_customize_tag_key(t *testing.T) {
|
func Test_customize_tag_key(t *testing.T) {
|
||||||
|
|
||||||
type TestObject struct {
|
type TestObject struct {
|
||||||
|
10
config.go
10
config.go
@ -11,6 +11,9 @@ import (
|
|||||||
"github.com/modern-go/reflect2"
|
"github.com/modern-go/reflect2"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
// limit maximum depth of nesting, as allowed by https://tools.ietf.org/html/rfc7159#section-9
|
||||||
|
const defaultMaxDepth = 10000
|
||||||
|
|
||||||
// Config customize how the API should behave.
|
// Config customize how the API should behave.
|
||||||
// The API is created from Config by Froze.
|
// The API is created from Config by Froze.
|
||||||
type Config struct {
|
type Config struct {
|
||||||
@ -25,6 +28,7 @@ type Config struct {
|
|||||||
ValidateJsonRawMessage bool
|
ValidateJsonRawMessage bool
|
||||||
ObjectFieldMustBeSimpleString bool
|
ObjectFieldMustBeSimpleString bool
|
||||||
CaseSensitive bool
|
CaseSensitive bool
|
||||||
|
MaxDepth int
|
||||||
}
|
}
|
||||||
|
|
||||||
// API the public interface of this package.
|
// API the public interface of this package.
|
||||||
@ -56,6 +60,7 @@ var ConfigCompatibleWithStandardLibrary = Config{
|
|||||||
EscapeHTML: true,
|
EscapeHTML: true,
|
||||||
SortMapKeys: true,
|
SortMapKeys: true,
|
||||||
ValidateJsonRawMessage: true,
|
ValidateJsonRawMessage: true,
|
||||||
|
MaxDepth: -1, // encoding/json has no max depth (stack overflow at 2581101)
|
||||||
}.Froze()
|
}.Froze()
|
||||||
|
|
||||||
// ConfigFastest marshals float with only 6 digits precision
|
// ConfigFastest marshals float with only 6 digits precision
|
||||||
@ -80,6 +85,7 @@ type frozenConfig struct {
|
|||||||
streamPool *sync.Pool
|
streamPool *sync.Pool
|
||||||
iteratorPool *sync.Pool
|
iteratorPool *sync.Pool
|
||||||
caseSensitive bool
|
caseSensitive bool
|
||||||
|
maxDepth int
|
||||||
}
|
}
|
||||||
|
|
||||||
func (cfg *frozenConfig) initCache() {
|
func (cfg *frozenConfig) initCache() {
|
||||||
@ -127,6 +133,9 @@ func addFrozenConfigToCache(cfg Config, frozenConfig *frozenConfig) {
|
|||||||
|
|
||||||
// Froze forge API from config
|
// Froze forge API from config
|
||||||
func (cfg Config) Froze() API {
|
func (cfg Config) Froze() API {
|
||||||
|
if cfg.MaxDepth == 0 {
|
||||||
|
cfg.MaxDepth = defaultMaxDepth
|
||||||
|
}
|
||||||
api := &frozenConfig{
|
api := &frozenConfig{
|
||||||
sortMapKeys: cfg.SortMapKeys,
|
sortMapKeys: cfg.SortMapKeys,
|
||||||
indentionStep: cfg.IndentionStep,
|
indentionStep: cfg.IndentionStep,
|
||||||
@ -134,6 +143,7 @@ func (cfg Config) Froze() API {
|
|||||||
onlyTaggedField: cfg.OnlyTaggedField,
|
onlyTaggedField: cfg.OnlyTaggedField,
|
||||||
disallowUnknownFields: cfg.DisallowUnknownFields,
|
disallowUnknownFields: cfg.DisallowUnknownFields,
|
||||||
caseSensitive: cfg.CaseSensitive,
|
caseSensitive: cfg.CaseSensitive,
|
||||||
|
maxDepth: cfg.MaxDepth,
|
||||||
}
|
}
|
||||||
api.streamPool = &sync.Pool{
|
api.streamPool = &sync.Pool{
|
||||||
New: func() interface{} {
|
New: func() interface{} {
|
||||||
|
5
iter.go
5
iter.go
@ -327,12 +327,9 @@ func (iter *Iterator) Read() interface{} {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// limit maximum depth of nesting, as allowed by https://tools.ietf.org/html/rfc7159#section-9
|
|
||||||
const maxDepth = 10000
|
|
||||||
|
|
||||||
func (iter *Iterator) incrementDepth() (success bool) {
|
func (iter *Iterator) incrementDepth() (success bool) {
|
||||||
iter.depth++
|
iter.depth++
|
||||||
if iter.depth <= maxDepth {
|
if iter.depth <= iter.cfg.maxDepth || iter.cfg.maxDepth < 0 {
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
iter.ReportError("incrementDepth", "exceeded max depth")
|
iter.ReportError("incrementDepth", "exceeded max depth")
|
||||||
|
Loading…
x
Reference in New Issue
Block a user