fix: Validate vetoed parameter type in feature RPC (#7583)

Co-authored-by: Mayukha Vadari <mvadari@ripple.com>
This commit is contained in:
Harshit Gupta
2026-10-06 19:44:56 +00:00
committed by GitHub
parent 718185e3b2
commit c2a4bc3aa1
3 changed files with 20 additions and 0 deletions

View File

@@ -36,6 +36,10 @@ Version 3.5.0 is not yet released.
- `channel_authorize`: The `channel_id` field now returns an `invalidParams` error if the value is not a string. [#7582](https://github.com/XRPLF/rippled/pull/7582)
- `channel_verify`: The `channel_id` and `signature` fields now return an `invalidParams` error if the value is not a string. [#7582](https://github.com/XRPLF/rippled/pull/7582)
### Bugfixes in 3.5.0
- `feature`: The admin-only `vetoed` field now returns `invalidParams` unless its value is a boolean. [#7583](https://github.com/XRPLF/rippled/pull/7583)
## XRP Ledger server version 3.4.0
Version 3.4.0 is not yet released. These changes are available in the 3.4.0 beta releases.

View File

@@ -506,7 +506,18 @@ class Feature_test : public beast::unit_test::Suite
feature = *(jrr.begin());
BEAST_EXPECTS(feature[jss::name] == kFeatureName, "name");
BEAST_EXPECTS(feature[jss::vetoed].isBool() && !feature[jss::vetoed].asBool(), "vetoed");
auto testInvalidVetoed = [&](auto const& vetoed) {
json::Value params;
params[jss::feature] = kFeatureName;
params[jss::vetoed] = vetoed;
auto const result = env.rpc("json", "feature", to_string(params))[jss::result];
BEAST_EXPECT(result[jss::error] == "invalidParams");
BEAST_EXPECT(result[jss::error_message] == "Invalid parameters.");
};
testInvalidVetoed("false");
testInvalidVetoed(json::Value(json::ValueType::Null));
// anything other than accept or reject is an error
jrr = env.rpc("feature", kFeatureName, "maybe");
BEAST_EXPECT(jrr[jss::error] == "invalidParams");

View File

@@ -64,6 +64,11 @@ doFeature(rpc::JsonContext& context)
if (!isAdmin)
return rpcError(RpcNoPermission);
if (!context.params[jss::vetoed].isBool())
{
return rpcError(RpcInvalidParams);
}
if (context.params[jss::vetoed].asBool())
{
table.veto(feature);