Problem/Motivation

List endpoints accept limit and offset style query parameters that flow into entity queries and Search API ranges. Without validation and an upper bound, a client can request an unbounded result set and exhaust memory, which is a denial-of-service vector.

Proposed resolution

  • Cast and validate every pagination parameter, rejecting non-numeric and negative values with 400 responses.
  • Enforce a configurable maximum page size with a conservative default.
  • Return consistent pagination metadata (total, page, page size) in every list response.

Remaining tasks

Centralise validation in MyrestResourceList and apply it to all list resources.

User interface changes

New maximum page size setting.

API changes

Out-of-range requests now return 400 instead of a large payload.

Issue fork myrest-3615472

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

sergeydruua created an issue. See original summary.

  • sergeydruua committed 8f08dfd4 on 1.0.x
    Issue #3615472: Validate and bound pagination parameters in list...
sergeydruua’s picture

Status: Active » Fixed

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

sergeydruua’s picture

Status: Fixed » Closed (fixed)