A06: enforce a server-side ceiling on List RPCs #18
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app#18
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
svclist handling passes the client limit straight through (internal/services/svc/list.go:18), andTable.List(0)means no limit. All seven entity List RPCs do this (event/list.go:27,user/list.go:20,item/list.go:27,reward/list.go:18,meal/list.go:17,itemlist/list.go:20,apikey/list.go:23,webhook/list.go:23). OnlyAuditLogcaps server-side (200 — the right pattern, applied once).All callers are authenticated and household-scale tables bound the damage, so this is hardening rather than a live hole.
Fix: clamp the effective limit in
svc.List(or per handler) to a sane ceiling, mirroring the AuditLog approach.Source: OWASP Top 10 (2025) audit of
v1.1.0, 2026-08-13. File references point at thev1.1.0tree.