From c2a4bc3aa1d3e2453f39463d5f470fb240d3eafb Mon Sep 17 00:00:00 2001 From: Harshit Gupta Date: Tue, 6 Oct 2026 19:44:56 +0000 Subject: [PATCH] fix: Validate vetoed parameter type in feature RPC (#7583) Co-authored-by: Mayukha Vadari --- API-CHANGELOG.md | 4 ++++ src/test/rpc/Feature_test.cpp | 11 +++++++++++ src/xrpld/rpc/handlers/server_info/Feature.cpp | 5 +++++ 3 files changed, 20 insertions(+) diff --git a/API-CHANGELOG.md b/API-CHANGELOG.md index 6b051888e5..ff0b39c7ac 100644 --- a/API-CHANGELOG.md +++ b/API-CHANGELOG.md @@ -36,6 +36,10 @@ Version 3.5.0 is not yet released. - `channel_authorize`: The `channel_id` field now returns an `invalidParams` error if the value is not a string. [#7582](https://github.com/XRPLF/rippled/pull/7582) - `channel_verify`: The `channel_id` and `signature` fields now return an `invalidParams` error if the value is not a string. [#7582](https://github.com/XRPLF/rippled/pull/7582) +### Bugfixes in 3.5.0 + +- `feature`: The admin-only `vetoed` field now returns `invalidParams` unless its value is a boolean. [#7583](https://github.com/XRPLF/rippled/pull/7583) + ## XRP Ledger server version 3.4.0 Version 3.4.0 is not yet released. These changes are available in the 3.4.0 beta releases. diff --git a/src/test/rpc/Feature_test.cpp b/src/test/rpc/Feature_test.cpp index 3304435afd..b38dea90fe 100644 --- a/src/test/rpc/Feature_test.cpp +++ b/src/test/rpc/Feature_test.cpp @@ -506,7 +506,18 @@ class Feature_test : public beast::unit_test::Suite feature = *(jrr.begin()); BEAST_EXPECTS(feature[jss::name] == kFeatureName, "name"); BEAST_EXPECTS(feature[jss::vetoed].isBool() && !feature[jss::vetoed].asBool(), "vetoed"); + auto testInvalidVetoed = [&](auto const& vetoed) { + json::Value params; + params[jss::feature] = kFeatureName; + params[jss::vetoed] = vetoed; + auto const result = env.rpc("json", "feature", to_string(params))[jss::result]; + BEAST_EXPECT(result[jss::error] == "invalidParams"); + BEAST_EXPECT(result[jss::error_message] == "Invalid parameters."); + }; + + testInvalidVetoed("false"); + testInvalidVetoed(json::Value(json::ValueType::Null)); // anything other than accept or reject is an error jrr = env.rpc("feature", kFeatureName, "maybe"); BEAST_EXPECT(jrr[jss::error] == "invalidParams"); diff --git a/src/xrpld/rpc/handlers/server_info/Feature.cpp b/src/xrpld/rpc/handlers/server_info/Feature.cpp index 0746194691..f537afadae 100644 --- a/src/xrpld/rpc/handlers/server_info/Feature.cpp +++ b/src/xrpld/rpc/handlers/server_info/Feature.cpp @@ -64,6 +64,11 @@ doFeature(rpc::JsonContext& context) if (!isAdmin) return rpcError(RpcNoPermission); + if (!context.params[jss::vetoed].isBool()) + { + return rpcError(RpcInvalidParams); + } + if (context.params[jss::vetoed].asBool()) { table.veto(feature);