mirror of
https://github.com/XRPLF/rippled.git
synced 2026-10-09 13:18:09 +00:00
fix: Validate vetoed parameter type in feature RPC (#7583)
Co-authored-by: Mayukha Vadari <mvadari@ripple.com>
This commit is contained in:
@@ -36,6 +36,10 @@ Version 3.5.0 is not yet released.
|
||||
- `channel_authorize`: The `channel_id` field now returns an `invalidParams` error if the value is not a string. [#7582](https://github.com/XRPLF/rippled/pull/7582)
|
||||
- `channel_verify`: The `channel_id` and `signature` fields now return an `invalidParams` error if the value is not a string. [#7582](https://github.com/XRPLF/rippled/pull/7582)
|
||||
|
||||
### Bugfixes in 3.5.0
|
||||
|
||||
- `feature`: The admin-only `vetoed` field now returns `invalidParams` unless its value is a boolean. [#7583](https://github.com/XRPLF/rippled/pull/7583)
|
||||
|
||||
## XRP Ledger server version 3.4.0
|
||||
|
||||
Version 3.4.0 is not yet released. These changes are available in the 3.4.0 beta releases.
|
||||
|
||||
@@ -506,7 +506,18 @@ class Feature_test : public beast::unit_test::Suite
|
||||
feature = *(jrr.begin());
|
||||
BEAST_EXPECTS(feature[jss::name] == kFeatureName, "name");
|
||||
BEAST_EXPECTS(feature[jss::vetoed].isBool() && !feature[jss::vetoed].asBool(), "vetoed");
|
||||
auto testInvalidVetoed = [&](auto const& vetoed) {
|
||||
json::Value params;
|
||||
params[jss::feature] = kFeatureName;
|
||||
params[jss::vetoed] = vetoed;
|
||||
|
||||
auto const result = env.rpc("json", "feature", to_string(params))[jss::result];
|
||||
BEAST_EXPECT(result[jss::error] == "invalidParams");
|
||||
BEAST_EXPECT(result[jss::error_message] == "Invalid parameters.");
|
||||
};
|
||||
|
||||
testInvalidVetoed("false");
|
||||
testInvalidVetoed(json::Value(json::ValueType::Null));
|
||||
// anything other than accept or reject is an error
|
||||
jrr = env.rpc("feature", kFeatureName, "maybe");
|
||||
BEAST_EXPECT(jrr[jss::error] == "invalidParams");
|
||||
|
||||
@@ -64,6 +64,11 @@ doFeature(rpc::JsonContext& context)
|
||||
if (!isAdmin)
|
||||
return rpcError(RpcNoPermission);
|
||||
|
||||
if (!context.params[jss::vetoed].isBool())
|
||||
{
|
||||
return rpcError(RpcInvalidParams);
|
||||
}
|
||||
|
||||
if (context.params[jss::vetoed].asBool())
|
||||
{
|
||||
table.veto(feature);
|
||||
|
||||
Reference in New Issue
Block a user