Repository navigation
Discovery: cap registered presentation size and raise the client response cap (backport of #4597) - #4608
Open
reinkrul wants to merge 1 commit into
Open
Discovery: cap registered presentation size and raise the client response cap (backport of #4597)#4608reinkrul wants to merge 1 commit into
reinkrul wants to merge 1 commit into
Conversation
… response cap (#4597) Backport of #4597 to V6.2. Registered Verifiable Presentations are now limited to 64 KiB, checked first in verifyRegistration and returned as ErrInvalidPresentation (HTTP 400). The Discovery Service client reads responses of up to 10 MiB from the operator-configured Discovery Server instead of the 1 MiB the strict HTTP client applies to all other outbound calls; the cap is now a per-client setting (WithMaxResponseSize), defaulting to the existing 1 MiB. Previously a client could no longer synchronize a service once a response exceeded 1 MiB, which a few hundred registrations, or two deliberately padded ones, could cause. Part of #4596 (cherry picked from commit 1b3d7c7) Assisted by AI
reinkrul
requested review from
gerardsn,
stevenvegt and
woutslakhorst
as code owners
October 5, 2026 13:01
Contributor
1 new issue
|
1 task
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport of #4597 to V6.2, tracked in #4596.
Clean cherry-pick of 1b3d7c7 apart from the release notes: V6.2 has no Unreleased section since v6.2.14 was released today, so one is added with the Security entry.
What
Module.verifyRegistrationand returned asErrInvalidPresentation(HTTP 400). Clients run the same check on downloaded entries.WithMaxResponseSize, default unchanged at 1 MiB).Why
Without it a client can no longer synchronize a service once a
GET /discovery/{serviceID}response exceeds 1 MiB, which a few hundred registrations, or two deliberately padded ones, can cause. Both the discovery module and the 1 MiB read cap (#3508) are present on V6.2.Testing
go build ./...and thehttp/clientanddiscovery/...suites pass on this branch.Assisted by AI