Closed (fixed)
Project:
MyREST
Version:
1.0.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
7 Aug 2026 at 13:41 UTC
Updated:
7 Aug 2026 at 13:58 UTC
Jump to comment: Most recent
List endpoints accept limit and offset style query parameters that flow into entity queries and Search API ranges. Without validation and an upper bound, a client can request an unbounded result set and exhaust memory, which is a denial-of-service vector.
Centralise validation in MyrestResourceList and apply it to all list resources.
New maximum page size setting.
Out-of-range requests now return 400 instead of a large payload.
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #4
sergeydruua commentedComment #6
sergeydruua commented