Allow configuring query parser#7375
Open
fenichelar wants to merge 3 commits intobalderdashy:masterfrom
Open
Conversation
|
Thanks for submitting this pull request, @fenichelar! We'll look at it ASAP. In the mean time, here are some ways you can help speed things along:
Please remember: never post in a public forum if you believe you've found a genuine security vulnerability. Instead, disclose it responsibly. For help with questions about Sails, click here. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview
This PR adds a new
httpconfiguration to sails calledqueryParser. If specified, this value is passed directly to express.A test where
queryParseris set tofalseto disable query parsing has also been added.Justification
There have been two recently security issues identified in
qs:To address these issues, enforcement of the
arrayLimithas been expanded to additional scenarios. The default value forarrayLimitinqsis20.expressdoes not set thearrayLimitwhen configuringqs, so the default value is used inexpress(and thereforesails) query parsing.Applications that were accepting long (greater than 20) query arrays with previous versions of
sailsare no longer able to accept these long query arrays.expressdoes not provide a way to change thearrayLimitvalue passed toqs, but it does provide the ability to override the query parser with a custom query parser (which could just beqsconfigured with a largerarrayLimit). However, this configuration ofexpressis not currently accessible tosailsapplications. This PR makes it accessible.