Skip to content

Discovery: cap registered presentation size and raise the client response cap (backport of #4597) - #4608

Open
reinkrul wants to merge 1 commit into
V6.2from
backport-4597-v6.2
Open

reinkrul wants to merge 1 commit into
V6.2from
backport-4597-v6.2

Conversation

@reinkrul

@reinkrul reinkrul commented Oct 5, 2026

Copy link
Copy Markdown
Member

Backport of #4597 to V6.2, tracked in #4596.

Clean cherry-pick of 1b3d7c7 apart from the release notes: V6.2 has no Unreleased section since v6.2.14 was released today, so one is added with the Security entry.

What

  • Server: registered Verifiable Presentations are limited to 64 KiB, checked first in Module.verifyRegistration and returned as ErrInvalidPresentation (HTTP 400). Clients run the same check on downloaded entries.
  • Client: the Discovery Service client reads responses of up to 10 MiB from the operator-configured Discovery Server. The strict HTTP client's response cap is now a per-client setting (WithMaxResponseSize, default unchanged at 1 MiB).
  • Docs paragraph and release notes entry.

Why

Without it a client can no longer synchronize a service once a GET /discovery/{serviceID} response exceeds 1 MiB, which a few hundred registrations, or two deliberately padded ones, can cause. Both the discovery module and the 1 MiB read cap (#3508) are present on V6.2.

Testing

go build ./... and the http/client and discovery/... suites pass on this branch.

Assisted by AI

… response cap (#4597)

Backport of #4597 to V6.2.

Registered Verifiable Presentations are now limited to 64 KiB, checked first in
verifyRegistration and returned as ErrInvalidPresentation (HTTP 400). The
Discovery Service client reads responses of up to 10 MiB from the
operator-configured Discovery Server instead of the 1 MiB the strict HTTP
client applies to all other outbound calls; the cap is now a per-client
setting (WithMaxResponseSize), defaulting to the existing 1 MiB.

Previously a client could no longer synchronize a service once a response
exceeded 1 MiB, which a few hundred registrations, or two deliberately padded
ones, could cause.

Part of #4596

(cherry picked from commit 1b3d7c7)

Assisted by AI
@qltysh

qltysh Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

1 new issue

Tool Category Rule Count
qlty Structure Function with many returns (count = 11): verifyRegistration 1

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant