A06: enforce a server-side ceiling on List RPCs #18

Closed
opened 2026-08-13 09:35:04 +00:00 by nalum · 0 comments
Owner

svc list handling passes the client limit straight through (internal/services/svc/list.go:18), and Table.List(0) means no limit. All seven entity List RPCs do this (event/list.go:27, user/list.go:20, item/list.go:27, reward/list.go:18, meal/list.go:17, itemlist/list.go:20, apikey/list.go:23, webhook/list.go:23). Only AuditLog caps server-side (200 — the right pattern, applied once).

All callers are authenticated and household-scale tables bound the damage, so this is hardening rather than a live hole.

Fix: clamp the effective limit in svc.List (or per handler) to a sane ceiling, mirroring the AuditLog approach.


Source: OWASP Top 10 (2025) audit of v1.1.0, 2026-08-13. File references point at the v1.1.0 tree.

`svc` list handling passes the client limit straight through (`internal/services/svc/list.go:18`), and `Table.List(0)` means no limit. All seven entity List RPCs do this (`event/list.go:27`, `user/list.go:20`, `item/list.go:27`, `reward/list.go:18`, `meal/list.go:17`, `itemlist/list.go:20`, `apikey/list.go:23`, `webhook/list.go:23`). Only `AuditLog` caps server-side (200 — the right pattern, applied once). All callers are authenticated and household-scale tables bound the damage, so this is hardening rather than a live hole. **Fix**: clamp the effective limit in `svc.List` (or per handler) to a sane ceiling, mirroring the AuditLog approach. --- Source: OWASP Top 10 (2025) audit of `v1.1.0`, 2026-08-13. File references point at the `v1.1.0` tree.
nalum added reference refs/tags/v1.1.0 2026-08-13 09:37:47 +00:00
nalum closed this issue 2026-08-13 11:38:29 +00:00
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#18
No description provided.