Compare commits

...

7 Commits

Author SHA1 Message Date
Bart
e2ce3de0fc fix: Select the reply envelope from a ripplerpc the server supports
The `ripplerpc` version is read in three places: twice inside the dispatch
loop to pick the error shape, and once after it to derive the HTTP status
by re-reading the version off the finished reply. Replace all three with
one `shapeReply` keyed by an `RpcVersion` enum naming the three envelopes.
The version is read once per request and passed in, and the status is
returned rather than read back, since only the function that wrote the
shape knows where the code went.

The version is now matched exactly against the three valid spellings, where
the `ripplerpc` string was compared with `>=` against "2.0" and "3.0", so
"abc" read as version 3 and "10.0" as version 1. Junk from an
unauthenticated client therefore chose an envelope, and at version 3 chose
real HTTP error codes. Anything but the three exact values is rejected with
a 400, the malformed-RPC fee and -32602, which is a break for API versions
1 and 2 on the JSON-RPC transport, listed under a breaking-changes heading
of its own in the changelog.

Hoisting the log statement above the shape branch fixes a second defect. It
read `error_message` after the version 2 and 3 branch renamed that member
to `message`, and reading a missing member non-const puts it back as an
explicit null, so an error reply carried `"error_message": null` exactly
when the `Server` log partition wrote at debug.
2026-10-10 20:02:26 +09:00
Bart
cf19602641 refactor: Answer every pre-dispatch rejection through one helper
Nine conditions reject a request before it reaches a handler, and seven
of them write their reply twice over: once as a plain-text body with an
HTTP status for a lone request, and once as an error object appended to
the reply array for a batch entry. The same fix has to be made seven
times, and another condition means another copy. Collapse them into one
`reject` helper that answers either shape and reports whether the loop has
more to do, so a caller reads `if (!reject(...)) return; continue;`.

Each shape is preserved exactly, including the asymmetry. Two of the nine
return the entry under `request`: the one naming an `api_version` the
server cannot serve, which asks for that shape through `wrapRequest`, and
an entry that is not an object, which stays inline, having no members to
carry an error. Six carry the error beside the entry's own members, and
`params unparsable` reaches a lone request only, that form's entries being
flat.

No reply changes. The codes these paths report are declared in
protocol/JsonRpc.h beside the protocol version, so the four file-local
copies go. The header declares every JSON-RPC error code this server
reports as one set, so three of them, `kJsonRpcInvalidRequest`,
`kJsonRpcInvalidParams` and `kJsonRpcServerError`, have no user until a
later branch reports them. The consumer now comes from
`requestInboundEndpoint`, which the WebSocket upgrade path already uses,
leaving the overload check as a condition beside the others rather than
nested inside endpoint construction. Two tests pin the shape a rejected
batch entry keeps: a null `method` reports `-32601` with `Null method`,
and an entry that is not an object is echoed under `request`. The suite
gains `overloadEndpoint`, which charges an address past the drop
threshold, for the privileged-request case.
2026-10-10 20:02:26 +09:00
Bart
fdcf2992d0 fix: Write a status line for every HTTP status a reply can report
`httpReply` names each status in a switch with no `default:` arm, and the
error table names two statuses that switch does not spell out: 402 for
`highFee` and 502 for `dbDeserialization`. A reply reporting either writes
no status line at all, so its first line is a header and the whole thing
is not an HTTP response. A client parsing it reads a protocol error rather
than the error the server meant to report.

Add the arm, taking the reason phrase from beast, which knows the whole
status registry, and drop the `bugprone-switch-missing-default-case`
suppression the omission needed. Eight of the arms above it then spell out
exactly what that arm produces, so they go. Three stay: 401 and 503 report
a phrase of this server's own, and 200 is what every successful reply
carries, so its line stays a compile-time literal rather than a
`std::format` call on the server's most common path.

Both statuses are reachable today through the `ripplerpc: "3.0"` envelope,
which derives the status from the error code. A gtest pins the status line
for every status this server sends, walks the error table, and reads the
placeholder line for a number the registry does not know, so a row added
with a new status cannot reintroduce the defect. A `sign` request whose
fee ceiling is zero reports `highFee` through that envelope, so the server
suite reads the 402 line end to end.
2026-10-10 20:02:25 +09:00
Bart
44a5da0632 fix: Give handler-specific RPC errors a code and message
Thirteen sites across five handlers assign `jss::error` a bare token,
skipping the `error_code`/`error_message` pair `rpc::injectError` sets.
Both consequences are visible on the wire: with no `error_code` the HTTP
status defaults to 200, so a load balancer sees success for a failed
request, and the version 2 envelope copies the pair unconditionally, so a
missing source produces an explicit `"code":null`/`"message":null`. Give
those tokens rows of their own, codes 100 to 109, and route every site
through `injectError`, preserving the `error_exception` detail `submit`
and `simulate` attach. `transaction_entry` keeps its four errors in the
handler's output as an rpc-spec `Status`, and `writeResult` reports each
through the status bridge, so the code and message land beside the ledger
fields the reply carries.

The `ledger_entry` helpers still report `invalidParams` (31) rather than
each token's own code. A version 1 or 2 client has read 31 for those
tokens for years, so changing it would break a client matching on the old
value; a comment on the helpers says so. `checkErrorValue` checks
`error_code` beside the token and the message, pinning each token's code
and failing on a token it does not know.

The `submit` and `simulate` arms reporting an internal error take no
coverage exclusion. Those arms are live, reached once
`NetworkOPs::processTransaction` or `Transaction::getJson` throws, and no
injection seam exists today, so the gap belongs in the test list rather
than behind a marker that hides it. Two more exclusions in `Simulate.cpp`
go, on arms that are live as well: the `Account` type check, which a
numeric `Account` reaches and a new `simulate` case sends, and the
fallback `engine_result` arm, which gets a comment saying why it stays.
2026-10-10 20:02:25 +09:00
Bart
db3764b231 fix: Give every error code an HTTP status
Four rows of the error table name no HTTP status, so the `ErrorInfo`
constructor defaults them to 200. The `ripplerpc: "3.0"` envelope derives
the status from the code, so a reply reporting an error claims success
and anything reading the status, a load balancer above all, reads success
too. Give all four one: `actNotFound` answers 404, matching every
`*NotFound` sibling but `entryNotFound`, and `actMalformed`,
`alreadyMultisig` and `alreadySingleSig` answer 400. Then drop the
constructor that defaulted a status, so no row can omit one again. A gtest
lists by hand the codes that have no row, so an enumerator added without
one fails it, and asserts that every other code names a status other than
200.

No client reads a new status here. `legacyHttpStatus` reports 200 for
exactly those four rows, so the 3.0 envelope answers what it always has.
That list is closed, naming the rows that had no status of their own, so
a row added later reports whatever the table says. The test suite names
the two statuses it compares against most, 200 and 400, as `kOk` and
`kBadRequest`, and every existing assertion on them uses the name.
2026-10-10 20:02:25 +09:00
Bart
5795eb3be2 style: Realign the error table
The columns of the error table had drifted apart as rows were added, so a reader scanning it follows a ragged edge and a new row has no alignment to copy. Realign all four columns on one set of widths inside the existing `clang-format off` guard, changing no row's content.
2026-10-10 16:41:14 +09:00
Bart
8eae0c338e fix: Mask every credential the server echoes, logs or prints
An error reply echoes the request that caused it, and masking covers four
fields at the top level of an object only. A `secret` nested inside
`params`, where the JSON-RPC transport puts it, comes back in the clear,
as does every other credential field at any depth, and only two sites
mask at all. Collect the names in one list and mask recursively, so
nesting stops mattering and a new field is added once. The list covers
the six names only a reply carries, which is how `wallet_propose` and
`validation_create` wrote a live key to the log; `validation_key` is the
same seed as `validation_seed` in RFC1751 words.

A log is an echo that outlives the reply, so one `loggable()` helper
masks and truncates together and every site that writes a request or a
reply out uses it, the `[rpc_startup]` command and its result included,
and the command line client logs the reply it receives parsed and
masked where it wrote the raw body, a `validation_create` answer among
them, and caps a body it cannot parse at the same length.
The `HTTP Reply` trace line in libxrpl, which cannot reach the masker,
now carries the status only; the body is logged beside it at debug,
masked when it carries a credential and otherwise as the string already
built for the wire, so a reply with no credential is serialized once. No
site logs an inbound request body uncapped, so the method name, bounded
by the request size limit, is the one thing a client chooses the length
of in the log. The request-duration line used to climb to warn and error
for a slow request with the request in it; the duration alone still
climbs, and the request stays at debug, so the duration line never lifts
text an anonymous client wrote to the default severity.

Three changes are visible to a caller. A credential in an echoed request
reads `<masked>` wherever it appears, nested inside `params` or a batch
entry too. The command line client masks `request_sent`, which carries
the `admin_password` it copies out of the config, so a failing
`./xrpld account_info rBogus` no longer prints a credential the operator
never typed. And a WebSocket frame that does not parse is answered with
its `size` rather than its body.
2026-10-10 16:35:23 +09:00
31 changed files with 2826 additions and 396 deletions

View File

@@ -174,8 +174,10 @@ test.server > xrpl.basics
test.server > xrpl.config
test.server > xrpld.app
test.server > xrpld.core
test.server > xrpld.rpc
test.server > xrpl.json
test.server > xrpl.protocol
test.server > xrpl.resource
test.server > xrpl.server
test.unit_test > xrpl.basics
test.unit_test > xrpl.protocol

View File

@@ -22,6 +22,22 @@ API version 2 is available in `xrpld` version 2.0.0 and later. See [API-VERSION-
This version is supported by all `xrpld` versions. For WebSocket and HTTP JSON-RPC requests, it is currently the default API version used when no `api_version` is specified.
## Unreleased
### Breaking changes
- The `ripplerpc` request field, which selects the shape of the JSON-RPC reply envelope, is now validated, and a value that is not exactly `"1.0"`, `"2.0"` or `"3.0"` is rejected. This reaches the JSON-RPC transport at every API version. It does not reach a WebSocket session, which reads the field only to echo it back. A request sending `"2"`, `" 2.0"`, `"2.00"`, `"02.0"`, `"2.0.0"`, `"10.0"` or any other text, such as `"abc"` or `"x2"`, gets a working reply today. After this ships, such a request sent alone gets HTTP 400 with `ripplerpc is not a supported version`, charged as a malformed request, and such an entry of a `"method": "batch"` body gets that error in its own reply while the batch answers 200. A client that spells the version loosely must therefore be corrected to one of the three exact values, or omit the field. Previously the value was compared as a string, which both accepted values that name no version and ordered multi-digit versions incorrectly: `"abc"` and `"x2"` sorted above `"3.0"` and so selected version 3, and `"10.0"` sorted below `"2.0"` and so selected version 1. Requests that send one of the three supported values, or omit the field, are unaffected.
### Bugfixes
- A request echoed back in an error reply now has every credential-bearing field masked: `admin_password`, `admin_user`, `passphrase`, `password`, `secret`, `seed`, `seed_hex`, `url_password`, `url_username` and `username`. Nesting no longer matters, so a credential inside `params` is masked too. The same masking is applied to every request and reply written to the log, and it covers six further names that only a reply carries: `master_key`, `master_seed`, `master_seed_hex`, `validation_key`, `validation_private_key` and `validation_seed`, which is how `wallet_propose` and `validation_create` used to write a live private key to the log. A request or reply written to the log is truncated at 10,000 characters.
- The command line client no longer prints a credential the operator did not type. A failing command echoes the request it built under `request_sent`, which carries the `admin_password` the client copies out of `[port_rpc]` in the config, so `./xrpld account_info rBogus` printed that password to stdout and into any captured output. `request_sent` is now masked. The `rpc` member beside it, which echoes the arguments as they were typed, is unchanged. The command line client also no longer writes an unparsed `json` or `ripple_path_find` argument to its trace log before parsing it, where a `secret` inside that argument could not be masked; it logs the parsed request instead, masked. The reply it receives is logged the same way, parsed and masked, where the raw body was written before, a `validation_create` answer included.
- A WebSocket frame that does not parse, or exceeds the request size limit, is answered `{"type": "error", "error": "jsonInvalid", "size": <bytes>}`. The frame's body is reported by size rather than echoed back in a `value` member, since a body that does not parse has no fields to mask. A client that read `value` gets `size` instead.
- Four error codes that named no HTTP status of their own, and so answered 200 on a reply reporting an error, now name one: `actMalformed`, `alreadyMultisig` and `alreadySingleSig` answer 400, and `actNotFound` answers 404. **No shipped envelope reports these four.** A request sending `ripplerpc: "3.0"` still receives 200 for all four, as it always has, so `account_info` on a malformed account or one the ledger does not hold answers 200 exactly as before.
- `submit`, `simulate`, `transaction_entry`, `ledger_entry` and `ledger_accept`: Errors from these methods now include `error_code` and `error_message` alongside the `error` token, as every other method already did. Each error now answers the status its code names: 400 for a malformed request, 404 for `transactionNotFound`, 500 for an internal failure, and 501 for `notYetImplemented` and `notStandAlone`. That status change reaches only a request sending `ripplerpc: "3.0"`, which is the envelope that derives the status from the error. With `ripplerpc` `"1.0"` the status stays 200 and the two new members appear beside `error`; with `"2.0"` the status stays 200, `error_code` appears, and the `code` and `message` members carry the code and the message rather than null, since that envelope copies them from `error_code` and `error_message` and drops `error_message`.
- A reply reporting HTTP 402 or 502 now carries a status line. Those two statuses named no case in the switch that writes one, so such a reply began with a header instead and did not parse as an HTTP response at all. Both are reachable at any API version with `ripplerpc: "3.0"`, which derives the status from the error code: 402 through `highFee` from `sign`, `sign_for` or `submit` with a low `fee_mult_max`, and 502 through `dbDeserialization` from `tx`. The eleven statuses that already named a case report the same phrase they always have.
- An error reply to a request sending `ripplerpc: "2.0"` or `"3.0"` no longer carries a stray `"error_message": null` beside the error it reports. The member appeared only when the `Server` log partition was set to debug or lower, because the log statement read `error_message` after the reply had renamed it to `message`, and reading it put it back as null. So the reply a client received depended on the server's log level, and the log line itself printed an empty message. Both are fixed.
## XRP Ledger server version 3.5.0
Version 3.5.0 is not yet released.

View File

@@ -144,7 +144,27 @@ enum ErrorCodeI {
RpcEntryNotFound = 98,
RpcUnexpectedLedgerType = 99,
RpcLast = RpcUnexpectedLedgerType // rpcLAST should always equal the last code.
// submit + simulate
RpcInvalidTransaction = 100,
RpcInternalSubmit = 101,
RpcInternalJson = 102,
RpcInternalSimulate = 103,
// transaction_entry
RpcFieldNotFoundTransaction = 104,
RpcNotYetImplemented = 105,
RpcTransactionNotFound = 106,
// transaction_entry + ledger_entry
RpcMalformedRequest = 107,
// ledger_accept
RpcNotStandAlone = 108,
// ledger_entry, API version 1 only
RpcUnknownOption = 109,
RpcLast = RpcUnknownOption // rpcLAST should always equal the last code.
};
/**
@@ -180,11 +200,6 @@ struct ErrorInfo
{
}
constexpr ErrorInfo(ErrorCodeI code, char const* token, char const* message)
: code(code), token(token), message(message), httpStatus(200)
{
}
constexpr ErrorInfo(ErrorCodeI code, char const* token, char const* message, int httpStatus)
: code(code), token(token), message(message), httpStatus(httpStatus)
{

View File

@@ -1,5 +1,7 @@
#pragma once
#include <xrpl/json/json_forwards.h>
#include <string_view>
namespace xrpl::rpc {
@@ -17,4 +19,25 @@ namespace xrpl::rpc {
*/
inline constexpr std::string_view kJsonRpcVersion{"2.0"};
/**
* Codes for the `code` member of a JSON-RPC error object.
*
* The specification reserves -32768 to -32000 for the protocol and leaves
* -32000 to -32099 of it to the implementation.
*
* kJsonRpcServerError is the code for an error an XRPL handler reports.
*
* The codes from kJsonRpcServerOverloaded on lie outside the
* implementation-defined sub-range, which the specification does not allow.
* They are the codes every shipped version reports, so moving one breaks the
* clients matching on it.
*/
inline constexpr json::Int kJsonRpcServerError{-32000};
inline constexpr json::Int kJsonRpcInvalidRequest{-32600};
inline constexpr json::Int kJsonRpcMethodNotFound{-32601};
inline constexpr json::Int kJsonRpcInvalidParams{-32602};
inline constexpr json::Int kJsonRpcServerOverloaded{-32604};
inline constexpr json::Int kJsonRpcForbidden{-32605};
inline constexpr json::Int kJsonRpcWrongVersion{-32606};
} // namespace xrpl::rpc

View File

@@ -245,7 +245,7 @@ JSS(ephemeral_key); // out: ValidatorInfo
JSS(error); // out: error
JSS(errored); //
JSS(error_code); // out: error
JSS(error_exception); // out: Submit
JSS(error_exception); // out: Submit, Simulate
JSS(error_message); // out: error
JSS(expand); // in: handler/Ledger
JSS(expected_date); // out: any (warnings)
@@ -559,7 +559,7 @@ JSS(signing_key); // out: NetworkOPs
JSS(signing_keys); // out: ValidatorList
JSS(signing_time); // out: NetworkOPs
JSS(signer_lists); // in/out: AccountInfo
JSS(size); // out: get_aggregate_price
JSS(size); // out: get_aggregate_price, ServerHandler
JSS(snapshot); // in: Subscribe
JSS(source_account); // in: PathRequest, RipplePathFind
JSS(source_amount); // in: PathRequest, RipplePathFind

View File

@@ -7,6 +7,20 @@
namespace xrpl {
/**
* Writes an HTTP reply carrying @p strMsg with status @p nStatus to @p output,
* and logs the status at trace. The body is not logged here: it may carry a
* credential this library cannot mask, so the caller logs it masked.
*
* A 401 with an empty body is answered with the fixed authentication page.
* The status line carries the phrase Beast's registry gives @p nStatus, except
* for 401 and 503, which carry a phrase of this server's own.
*
* @param nStatus The HTTP status code.
* @param strMsg The body.
* @param output Where the reply bytes are written.
* @param j The journal the status is logged to.
*/
void
httpReply(int nStatus, std::string const& strMsg, json::Output const&, beast::Journal j);

View File

@@ -20,88 +20,102 @@ namespace detail {
// will remain in the object file. But the string literals will remain.
//
// There's a certain amount of tension in determining the correct HTTP
// status to associate with a given RPC error. Initially all RPC errors
// returned 200 (OK). And that's the default behavior if no HTTP status code
// is specified below.
// status to associate with a given RPC error. Every row below names its
// HTTP status, and a row that omits it does not compile, since ErrorInfo has
// no constructor that leaves the status out.
//
// The codes currently selected target the load balancer fail-over use case.
// If a query fails on one node but is likely to have a positive outcome
// on a different node, then the failure should return a 4xx/5xx range
// status code.
// The rows below are aligned by hand into four columns, so that a wrong status or a mistyped token
// is visible by scanning one column. That cannot be had inside the 100-column limit once the
// longest enumerator and the longest message sit in one row. So this region is exempt from the
// limit by design rather than by oversight.
// clang-format off
static constexpr ErrorInfo kUnorderedErrorInfos[]{
{RpcActMalformed, "actMalformed", "Account malformed."},
{RpcActNotFound, "actNotFound", "Account not found."},
{RpcAlreadyMultisig, "alreadyMultisig", "Already multisigned."},
{RpcAlreadySingleSig, "alreadySingleSig", "Already single-signed."},
{RpcAmendmentBlocked, "amendmentBlocked", "Amendment blocked, need upgrade.", 503},
{RpcExpiredValidatorList, "unlBlocked", "Validator list expired.", 503},
{RpcAtxDeprecated, "deprecated", "Use the new API or specify a ledger range.", 400},
{RpcBadKeyType, "badKeyType", "Bad key type.", 400},
{RpcBadFeature, "badFeature", "Feature unknown or invalid.", 500},
{RpcBadIssuer, "badIssuer", "Issuer account malformed.", 400},
{RpcBadMarket, "badMarket", "No such market.", 404},
{RpcBadSecret, "badSecret", "Secret does not match account.", 403},
{RpcBadSeed, "badSeed", "Disallowed seed.", 403},
{RpcBadSyntax, "badSyntax", "Syntax error.", 400},
{RpcChannelMalformed, "channelMalformed", "Payment channel is malformed.", 400},
{RpcChannelAmtMalformed, "channelAmtMalformed", "Payment channel amount is malformed.", 400},
{RpcCommandMissing, "commandMissing", "Missing command entry.", 400},
{RpcDbDeserialization, "dbDeserialization", "Database deserialization error.", 502},
{RpcDstActMalformed, "dstActMalformed", "Destination account is malformed.", 400},
{RpcDstActMissing, "dstActMissing", "Destination account not provided.", 400},
{RpcDstActNotFound, "dstActNotFound", "Destination account not found.", 404},
{RpcDstAmtMalformed, "dstAmtMalformed", "Destination amount/currency/issuer is malformed.", 400},
{RpcDstAmtMissing, "dstAmtMissing", "Destination amount/currency/issuer is missing.", 400},
{RpcDstIsrMalformed, "dstIsrMalformed", "Destination issuer is malformed.", 400},
{RpcExcessiveLgrRange, "excessiveLgrRange", "Ledger range exceeds 1000.", 400},
{RpcForbidden, "forbidden", "Bad credentials.", 403},
{RpcHighFee, "highFee", "Current transaction fee exceeds your limit.", 402},
{RpcInternal, "internal", "Internal error.", 500},
{RpcInvalidLgrRange, "invalidLgrRange", "Ledger range is invalid.", 400},
{RpcInvalidParams, "invalidParams", "Invalid parameters.", 400},
{RpcInvalidHotwallet, "invalidHotWallet", "Invalid hotwallet.", 400},
{RpcIssueMalformed, "issueMalformed", "Issue is malformed.", 400},
{RpcJsonRpc, "json_rpc", "JSON-RPC transport error.", 500},
{RpcLgrIdxsInvalid, "lgrIdxsInvalid", "Ledger indexes invalid.", 400},
{RpcLgrIdxMalformed, "lgrIdxMalformed", "Ledger index malformed.", 400},
{RpcLgrNotFound, "lgrNotFound", "Ledger not found.", 404},
{RpcLgrNotValidated, "lgrNotValidated", "Ledger not validated.", 202},
{RpcMasterDisabled, "masterDisabled", "Master key is disabled.", 403},
{RpcNotEnabled, "notEnabled", "Not enabled in configuration.", 501},
{RpcNotImpl, "notImpl", "Not implemented.", 501},
{RpcNotReady, "notReady", "Not ready to handle this request.", 503},
{RpcNotSupported, "notSupported", "Operation not supported.", 501},
{RpcNoClosed, "noClosed", "Closed ledger is unavailable.", 503},
{RpcNoCurrent, "noCurrent", "Current ledger is unavailable.", 503},
{RpcNotSynced, "notSynced", "Not synced to the network.", 503},
{RpcNoEvents, "noEvents", "Current transport does not support events.", 405},
{RpcNoNetwork, "noNetwork", "Not synced to the network.", 503},
{RpcWrongNetwork, "wrongNetwork", "Wrong network.", 503},
{RpcNoPermission, "noPermission", "You don't have permission for this command.", 401},
{RpcNoPfRequest, "noPathRequest", "No pathfinding request in progress.", 404},
{RpcObjectNotFound, "objectNotFound", "The requested object was not found.", 404},
{RpcPublicMalformed, "publicMalformed", "Public key is malformed.", 400},
{RpcSendmaxMalformed, "sendMaxMalformed", "SendMax amount malformed.", 400},
{RpcSigningMalformed, "signingMalformed", "Signing of transaction is malformed.", 400},
{RpcSlowDown, "slowDown", "You are placing too much load on the server.", 429},
{RpcSrcActMalformed, "srcActMalformed", "Source account is malformed.", 400},
{RpcSrcActMissing, "srcActMissing", "Source account not provided.", 400},
{RpcSrcActNotFound, "srcActNotFound", "Source account not found.", 404},
{RpcDelegateActNotFound, "delegateActNotFound", "Delegate account not found.", 404},
{RpcSrcCurMalformed, "srcCurMalformed", "Source currency is malformed.", 400},
{RpcSrcIsrMalformed, "srcIsrMalformed", "Source issuer is malformed.", 400},
{RpcStreamMalformed, "malformedStream", "Stream malformed.", 400},
{RpcTooBusy, "tooBusy", "The server is too busy to help you now.", 503},
{RpcTxnNotFound, "txnNotFound", "Transaction not found.", 404},
{RpcUnknownCommand, "unknownCmd", "Unknown method.", 405},
{RpcOracleMalformed, "oracleMalformed", "Oracle request is malformed.", 400},
{RpcBadCredentials, "badCredentials", "Credentials do not exist, are not accepted, or have expired.", 400},
{RpcTxSigned, "transactionSigned", "Transaction should not be signed.", 400},
{RpcDomainMalformed, "domainMalformed", "Domain is malformed.", 400},
{RpcEntryNotFound, "entryNotFound", "Entry not found.", 400},
{RpcUnexpectedLedgerType, "unexpectedLedgerType", "Unexpected ledger type.", 400},
{RpcActMalformed, "actMalformed", "Account malformed.", 400},
{RpcActNotFound, "actNotFound", "Account not found.", 404},
{RpcAlreadyMultisig, "alreadyMultisig", "Already multisigned.", 400},
{RpcAlreadySingleSig, "alreadySingleSig", "Already single-signed.", 400},
{RpcAmendmentBlocked, "amendmentBlocked", "Amendment blocked, need upgrade.", 503},
{RpcExpiredValidatorList, "unlBlocked", "Validator list expired.", 503},
{RpcAtxDeprecated, "deprecated", "Use the new API or specify a ledger range.", 400},
{RpcBadKeyType, "badKeyType", "Bad key type.", 400},
{RpcBadFeature, "badFeature", "Feature unknown or invalid.", 500},
{RpcBadIssuer, "badIssuer", "Issuer account malformed.", 400},
{RpcBadMarket, "badMarket", "No such market.", 404},
{RpcBadSecret, "badSecret", "Secret does not match account.", 403},
{RpcBadSeed, "badSeed", "Disallowed seed.", 403},
{RpcBadSyntax, "badSyntax", "Syntax error.", 400},
{RpcChannelMalformed, "channelMalformed", "Payment channel is malformed.", 400},
{RpcChannelAmtMalformed, "channelAmtMalformed", "Payment channel amount is malformed.", 400},
{RpcCommandMissing, "commandMissing", "Missing command entry.", 400},
{RpcDbDeserialization, "dbDeserialization", "Database deserialization error.", 502},
{RpcDstActMalformed, "dstActMalformed", "Destination account is malformed.", 400},
{RpcDstActMissing, "dstActMissing", "Destination account not provided.", 400},
{RpcDstActNotFound, "dstActNotFound", "Destination account not found.", 404},
{RpcDstAmtMalformed, "dstAmtMalformed", "Destination amount/currency/issuer is malformed.", 400},
{RpcDstAmtMissing, "dstAmtMissing", "Destination amount/currency/issuer is missing.", 400},
{RpcDstIsrMalformed, "dstIsrMalformed", "Destination issuer is malformed.", 400},
{RpcExcessiveLgrRange, "excessiveLgrRange", "Ledger range exceeds 1000.", 400},
{RpcForbidden, "forbidden", "Bad credentials.", 403},
{RpcHighFee, "highFee", "Current transaction fee exceeds your limit.", 402},
{RpcInternal, "internal", "Internal error.", 500},
{RpcInvalidLgrRange, "invalidLgrRange", "Ledger range is invalid.", 400},
{RpcInvalidParams, "invalidParams", "Invalid parameters.", 400},
{RpcInvalidHotwallet, "invalidHotWallet", "Invalid hotwallet.", 400},
{RpcIssueMalformed, "issueMalformed", "Issue is malformed.", 400},
{RpcJsonRpc, "json_rpc", "JSON-RPC transport error.", 500},
{RpcLgrIdxsInvalid, "lgrIdxsInvalid", "Ledger indexes invalid.", 400},
{RpcLgrIdxMalformed, "lgrIdxMalformed", "Ledger index malformed.", 400},
{RpcLgrNotFound, "lgrNotFound", "Ledger not found.", 404},
{RpcLgrNotValidated, "lgrNotValidated", "Ledger not validated.", 202},
{RpcMasterDisabled, "masterDisabled", "Master key is disabled.", 403},
{RpcNotEnabled, "notEnabled", "Not enabled in configuration.", 501},
{RpcNotImpl, "notImpl", "Not implemented.", 501},
{RpcNotReady, "notReady", "Not ready to handle this request.", 503},
{RpcNotSupported, "notSupported", "Operation not supported.", 501},
{RpcNoClosed, "noClosed", "Closed ledger is unavailable.", 503},
{RpcNoCurrent, "noCurrent", "Current ledger is unavailable.", 503},
{RpcNotSynced, "notSynced", "Not synced to the network.", 503},
{RpcNoEvents, "noEvents", "Current transport does not support events.", 405},
{RpcNoNetwork, "noNetwork", "Not synced to the network.", 503},
{RpcWrongNetwork, "wrongNetwork", "Wrong network.", 503},
{RpcNoPermission, "noPermission", "You don't have permission for this command.", 401},
{RpcNoPfRequest, "noPathRequest", "No pathfinding request in progress.", 404},
{RpcObjectNotFound, "objectNotFound", "The requested object was not found.", 404},
{RpcPublicMalformed, "publicMalformed", "Public key is malformed.", 400},
{RpcSendmaxMalformed, "sendMaxMalformed", "SendMax amount malformed.", 400},
{RpcSigningMalformed, "signingMalformed", "Signing of transaction is malformed.", 400},
{RpcSlowDown, "slowDown", "You are placing too much load on the server.", 429},
{RpcSrcActMalformed, "srcActMalformed", "Source account is malformed.", 400},
{RpcSrcActMissing, "srcActMissing", "Source account not provided.", 400},
{RpcSrcActNotFound, "srcActNotFound", "Source account not found.", 404},
{RpcDelegateActNotFound, "delegateActNotFound", "Delegate account not found.", 404},
{RpcSrcCurMalformed, "srcCurMalformed", "Source currency is malformed.", 400},
{RpcSrcIsrMalformed, "srcIsrMalformed", "Source issuer is malformed.", 400},
{RpcStreamMalformed, "malformedStream", "Stream malformed.", 400},
{RpcTooBusy, "tooBusy", "The server is too busy to help you now.", 503},
{RpcTxnNotFound, "txnNotFound", "Transaction not found.", 404},
{RpcUnknownCommand, "unknownCmd", "Unknown method.", 405},
{RpcOracleMalformed, "oracleMalformed", "Oracle request is malformed.", 400},
{RpcBadCredentials, "badCredentials", "Credentials do not exist, are not accepted, or have expired.", 400},
{RpcTxSigned, "transactionSigned", "Transaction should not be signed.", 400},
{RpcDomainMalformed, "domainMalformed", "Domain is malformed.", 400},
{RpcEntryNotFound, "entryNotFound", "Entry not found.", 400},
{RpcUnexpectedLedgerType, "unexpectedLedgerType", "Unexpected ledger type.", 400},
{RpcInvalidTransaction, "invalidTransaction", "Transaction is invalid.", 400},
{RpcInternalSubmit, "internalSubmit", "Internal error during submit.", 500},
{RpcInternalJson, "internalJson", "Internal error during JSON handling.", 500},
{RpcInternalSimulate, "internalSimulate", "Internal error during simulate.", 500},
{RpcFieldNotFoundTransaction, "fieldNotFoundTransaction", "Missing required field.", 400},
{RpcNotYetImplemented, "notYetImplemented", "Not yet implemented.", 501},
{RpcTransactionNotFound, "transactionNotFound", "Transaction not found.", 404},
{RpcMalformedRequest, "malformedRequest", "Request is malformed.", 400},
{RpcNotStandAlone, "notStandAlone", "Server is not running stand-alone.", 501},
{RpcUnknownOption, "unknownOption", "Unknown option.", 400},
};
// clang-format on

View File

@@ -6,7 +6,10 @@
#include <xrpl/protocol/BuildInfo.h>
#include <xrpl/protocol/SystemParameters.h>
#include <boost/beast/http/status.hpp>
#include <ctime>
#include <format>
#include <string>
namespace xrpl {
@@ -33,7 +36,10 @@ getHTTPHeaderTimestamp()
void
httpReply(int nStatus, std::string const& content, json::Output const& output, beast::Journal j)
{
JLOG(j.trace()) << "HTTP Reply " << nStatus << " " << content;
// The status only. The body is a reply, which carries a credential when the
// command is a keygen, and this library cannot mask one: the caller logs the
// masked body at debug.
JLOG(j.trace()) << "HTTP Reply " << nStatus;
if (content.empty() && nStatus == 401)
{
@@ -69,42 +75,29 @@ httpReply(int nStatus, std::string const& content, json::Output const& output, b
return;
}
// NOLINTNEXTLINE(bugprone-switch-missing-default-case)
switch (nStatus)
{
// The status every successful reply carries, so a literal rather than a format call.
case 200:
output("HTTP/1.1 200 OK\r\n");
break;
case 202:
output("HTTP/1.1 202 Accepted\r\n");
break;
case 400:
output("HTTP/1.1 400 Bad Request\r\n");
break;
// Two statuses this server phrases itself rather than taking from the registry.
case 401:
output("HTTP/1.1 401 Authorization Required\r\n");
break;
case 403:
output("HTTP/1.1 403 Forbidden\r\n");
break;
case 404:
output("HTTP/1.1 404 Not Found\r\n");
break;
case 405:
output("HTTP/1.1 405 Method Not Allowed\r\n");
break;
case 429:
output("HTTP/1.1 429 Too Many Requests\r\n");
break;
case 500:
output("HTTP/1.1 500 Internal Server Error\r\n");
break;
case 501:
output("HTTP/1.1 501 Not Implemented\r\n");
break;
case 503:
output("HTTP/1.1 503 Server is overloaded\r\n");
break;
default:
// A reply whose first line is a header is not an HTTP response. Beast knows the whole
// registry, so a status the error table gains needs no case here.
output(
std::format(
"HTTP/1.1 {} {}\r\n",
nStatus,
boost::beast::http::obsolete_reason(
static_cast<boost::beast::http::status>(nStatus))));
break;
}
output(getHTTPHeaderTimestamp());

View File

@@ -56,8 +56,10 @@
#include <chrono>
#include <cstddef>
#include <cstdint>
#include <map>
#include <memory>
#include <optional>
#include <set>
#include <source_location>
#include <stdexcept>
#include <string>
@@ -164,6 +166,68 @@ class LedgerEntry_test : public beast::unit_test::Suite
jv[jss::error] == err,
"Expected error " + err + ", received " + jv[jss::error].asString() + ", at line " +
std::to_string(location.line()) + ", " + jv.toStyledString());
// Wire values pinned as literals: read from the error table, the expectation would
// agree with any change to the row that produced the reply.
// These are raised through injectError and carry their own code.
static std::map<std::string, int> const kCodes{
{"entryNotFound", 98},
{"invalidParams", 31},
{"lgrNotFound", 21},
{"unexpectedLedgerType", 99},
{"unknownOption", 109},
};
// The tokens the ledger_entry helpers name, all reporting the generic invalidParams;
// see LedgerEntryHelpers.h. Listed, so a misspelled token reaches the else below.
static std::set<std::string> const kMalformedTokens{
"malformedAccount",
"malformedAddress",
"malformedAuthorized",
"malformedAuthorizedCredentials",
"malformedBridgeAccount",
"malformedBroker",
"malformedCurrency",
"malformedDirRoot",
"malformedDocumentID",
"malformedIssue",
"malformedIssuingChainDoor",
"malformedLockingChainDoor",
"malformedMPTIssuanceID",
"malformedMPTokenIssuance",
"malformedOwner",
"malformedRequest",
"malformedSeq",
"malformedSponsee",
"malformedSponsor",
"malformedXChainOwnedClaimID",
"malformedXChainOwnedCreateAccountClaimID",
};
auto const expectCode = [&](int expected) {
BEAST_EXPECTS(
jv[jss::error_code] == expected,
"Expected error_code " + std::to_string(expected) + " for " + err +
", received " + jv[jss::error_code].toStyledString() + ", at line " +
std::to_string(location.line()));
};
if (auto const it = kCodes.find(err); it != kCodes.end())
{
expectCode(it->second);
}
else if (kMalformedTokens.contains(err))
{
expectCode(RpcInvalidParams);
}
else
{
// A token in neither list is a typo; reporting 31 like the rest would let it pass.
BEAST_EXPECTS(
false,
"Token " + err + " names no error code, at line " +
std::to_string(location.line()));
}
}
if (msg.empty())
{
@@ -340,7 +404,7 @@ class LedgerEntry_test : public beast::unit_test::Suite
apiVersion, "json", "ledger_entry", to_string(correctRequest))[jss::result];
if (apiVersion < 2u)
{
checkErrorValue(jrr, "unknownOption", "", location);
checkErrorValue(jrr, "unknownOption", "Unknown option.", location);
}
else
{
@@ -546,7 +610,7 @@ class LedgerEntry_test : public beast::unit_test::Suite
if (apiVersion < 2u)
{
checkErrorValue(jrr, "unknownOption", "");
checkErrorValue(jrr, "unknownOption", "Unknown option.");
}
else
{

View File

@@ -0,0 +1,397 @@
#include <test/jtx/Env.h>
#include <xrpld/rpc/detail/MaskSecrets.h>
#include <xrpl/beast/unit_test/suite.h>
#include <xrpl/json/json_reader.h>
#include <xrpl/json/json_value.h>
#include <xrpl/json/to_string.h>
#include <xrpl/protocol/jss.h>
#include <algorithm>
#include <array>
#include <string>
#include <string_view>
namespace xrpl::test {
class MaskSecrets_test : public beast::unit_test::Suite
{
static constexpr char const* kMasked = "<masked>";
static constexpr char const* kSensitive = "sensitive";
public:
/**
* Every field in `kCredentialFields` is masked, at the top level.
*/
void
testEveryCredentialField()
{
testcase("Every credential field is masked");
json::Value request(json::ValueType::Object);
for (auto const field : rpc::kCredentialFields)
request[std::string{field}] = kSensitive;
auto const masked = rpc::maskSecrets(request);
for (auto const field : rpc::kCredentialFields)
BEAST_EXPECTS(masked[std::string{field}] == kMasked, std::string{field});
// An empty list would let every assertion above pass while masking nothing.
BEAST_EXPECT(!rpc::kCredentialFields.empty());
}
/**
* A field the list does not name is left as it was.
*/
void
testNonCredentialsSurvive()
{
testcase("Fields that are not credentials are left alone");
json::Value request(json::ValueType::Object);
request[jss::method] = "sign";
request[jss::account] = "rSomeAccount";
request[jss::secret] = kSensitive;
auto const masked = rpc::maskSecrets(request);
BEAST_EXPECT(masked[jss::secret] == kMasked);
BEAST_EXPECT(masked[jss::method] == "sign");
BEAST_EXPECT(masked[jss::account] == "rSomeAccount");
// Masking replaces members rather than adding or removing them.
BEAST_EXPECT(masked.size() == request.size());
}
/**
* A member name is matched whole, not as a substring or case-insensitively.
*/
void
testNamesAreMatchedExactly()
{
testcase("Only an exact field name is masked");
json::Value request(json::ValueType::Object);
for (auto const* name : {"secrets", "Secret", "my_secret", "seedling", "sec", ""})
request[name] = kSensitive;
auto const masked = rpc::maskSecrets(request);
for (auto const* name : {"secrets", "Secret", "my_secret", "seedling", "sec", ""})
BEAST_EXPECTS(masked[name] == kSensitive, name);
}
/**
* A credential is masked wherever it sits, not only at the top level.
*
* The JSON-RPC transport nests a request's fields inside `params`, which is
* where a `secret` arrives.
*/
void
testNesting()
{
testcase("A nested credential is masked at any depth");
// Where the JSON-RPC transport carries a credential: inside `params`.
{
json::Value params(json::ValueType::Object);
params[jss::secret] = kSensitive;
params[jss::account] = "rSomeAccount";
json::Value request(json::ValueType::Object);
request[jss::method] = "sign";
request[jss::params] = json::ValueType::Array;
request[jss::params][0u] = params;
auto const masked = rpc::maskSecrets(request);
BEAST_EXPECT(masked[jss::params][0u][jss::secret] == kMasked);
BEAST_EXPECT(masked[jss::params][0u][jss::account] == "rSomeAccount");
BEAST_EXPECT(masked[jss::method] == "sign");
}
// Where a batch carries one: inside an entry, itself inside `params`.
{
json::Value entry(json::ValueType::Object);
entry[jss::id] = 2;
entry[jss::seed] = kSensitive;
json::Value batch(json::ValueType::Object);
batch[jss::method] = "batch";
batch[jss::params] = json::ValueType::Array;
batch[jss::params][0u] = entry;
auto const masked = rpc::maskSecrets(batch);
BEAST_EXPECT(masked[jss::params][0u][jss::seed] == kMasked);
BEAST_EXPECT(masked[jss::params][0u][jss::id] == 2);
}
// A credential in an array element, which names no member of its own.
{
json::Value inner(json::ValueType::Object);
inner[jss::passphrase] = kSensitive;
json::Value request(json::ValueType::Array);
request[0u] = inner;
auto const masked = rpc::maskSecrets(request);
BEAST_EXPECT(masked[0u][jss::passphrase] == kMasked);
}
// Up to the parser's nesting limit, which is what bounds the recursion.
{
json::Value deep(json::ValueType::Object);
deep[jss::secret] = kSensitive;
for (unsigned i{0}; i < json::Reader::kNestLimit; ++i)
{
json::Value outer(json::ValueType::Object);
outer[jss::params] = deep;
deep = outer;
}
auto const masked = rpc::maskSecrets(deep);
auto const* level = &masked;
for (unsigned i{0}; i < json::Reader::kNestLimit; ++i)
level = &(*level)[jss::params];
BEAST_EXPECT((*level)[jss::secret] == kMasked);
}
}
/**
* A credential's own value is replaced whole, whatever shape it has.
*
* An object or array under `secret` is not walked into: the whole value is
* the credential.
*/
void
testCredentialIsNotDescendedInto()
{
testcase("A credential is replaced whatever it holds");
json::Value nested(json::ValueType::Object);
nested["inner"] = kSensitive;
json::Value request(json::ValueType::Object);
request[jss::secret] = nested;
request[jss::seed] = json::ValueType::Array;
request[jss::seed][0u] = kSensitive;
auto const masked = rpc::maskSecrets(request);
BEAST_EXPECT(masked[jss::secret] == kMasked);
BEAST_EXPECT(masked[jss::seed] == kMasked);
BEAST_EXPECT(!to_string(masked).contains(kSensitive));
}
/**
* A credential that is not a string is masked too, the value being replaced
* whole.
*/
void
testNonStringCredentials()
{
testcase("A credential of any type is masked");
json::Value request(json::ValueType::Object);
request["secret"] = 12345;
request["seed"] = true;
request["passphrase"] = 1.5;
request["password"] = json::ValueType::Null;
auto const masked = rpc::maskSecrets(request);
for (auto const* field : {"secret", "seed", "passphrase", "password"})
BEAST_EXPECTS(masked[field] == kMasked, field);
}
/**
* A value with no members is returned unchanged, masking keying on member
* names.
*/
void
testValuesWithoutMembers()
{
testcase("A value that has no members is returned unchanged");
BEAST_EXPECT(rpc::maskSecrets(json::Value{}).isNull());
BEAST_EXPECT(rpc::maskSecrets(json::Value{kSensitive}) == kSensitive);
BEAST_EXPECT(rpc::maskSecrets(json::Value{42}) == 42);
BEAST_EXPECT(rpc::maskSecrets(json::Value{json::ValueType::Object}).size() == 0);
BEAST_EXPECT(rpc::maskSecrets(json::Value{json::ValueType::Array}).size() == 0);
}
/**
* The request the caller passed in is not modified.
*
* Every call site goes on to use the request it holds, so the mask copies.
*/
void
testRequestIsNotModified()
{
testcase("The request passed in is left unchanged");
json::Value request(json::ValueType::Object);
request[jss::secret] = kSensitive;
request[jss::params] = json::ValueType::Array;
request[jss::params][0u] = json::ValueType::Object;
request[jss::params][0u][jss::seed] = kSensitive;
auto const before = to_string(request);
auto const masked = rpc::maskSecrets(request);
BEAST_EXPECT(to_string(request) == before);
BEAST_EXPECT(request[jss::secret] == kSensitive);
BEAST_EXPECT(request[jss::params][0u][jss::seed] == kSensitive);
BEAST_EXPECT(masked[jss::secret] == kMasked);
}
/**
* `hasSecret` reports a credential at any depth and nothing else.
*
* Every name on the list is reported at the top level, one nested where the
* JSON-RPC transport puts it and one inside an array element are reported
* too, and a value naming none, or having no members at all, is not.
*/
void
testHasSecret()
{
testcase("A credential is detected at any depth");
for (auto const field : rpc::kCredentialFields)
{
json::Value request(json::ValueType::Object);
request[std::string{field}] = kSensitive;
BEAST_EXPECTS(rpc::hasSecret(request), std::string{field});
}
// Inside `params`, where the JSON-RPC transport carries a credential.
{
json::Value request(json::ValueType::Object);
request[jss::method] = "sign";
request[jss::params] = json::ValueType::Array;
request[jss::params][0u] = json::ValueType::Object;
request[jss::params][0u][jss::account] = "rSomeAccount";
request[jss::params][0u][jss::secret] = kSensitive;
BEAST_EXPECT(rpc::hasSecret(request));
}
// Inside an array element, which names no member of its own.
{
json::Value request(json::ValueType::Array);
request[0u] = json::ValueType::Object;
request[0u][jss::passphrase] = kSensitive;
BEAST_EXPECT(rpc::hasSecret(request));
}
// No credential at any depth, and a near miss is not one.
{
json::Value request(json::ValueType::Object);
request[jss::method] = "account_info";
request[jss::params] = json::ValueType::Array;
request[jss::params][0u] = json::ValueType::Object;
request[jss::params][0u][jss::account] = "rSomeAccount";
request[jss::params][0u]["secrets"] = kSensitive;
BEAST_EXPECT(!rpc::hasSecret(request));
}
// A value with no members carries none.
BEAST_EXPECT(!rpc::hasSecret(json::Value{}));
BEAST_EXPECT(!rpc::hasSecret(json::Value{kSensitive}));
BEAST_EXPECT(!rpc::hasSecret(json::Value{42}));
BEAST_EXPECT(!rpc::hasSecret(json::Value{json::ValueType::Object}));
BEAST_EXPECT(!rpc::hasSecret(json::Value{json::ValueType::Array}));
}
/**
* `loggable` masks a value that carries a credential, then truncates at
* `kMaxLoggedChars`; one that carries none is rendered as it is.
*
* The mask has to survive the cap, so the credential is placed where a
* sorted member order puts it first.
*/
void
testLoggable()
{
testcase("A rendering for a log line is masked and capped");
// Sorts before the filler, so the mask falls inside the cap.
json::Value request;
request[jss::secret] = kSensitive;
request["zfiller"] = std::string(2 * rpc::kMaxLoggedChars, 'z');
auto const rendered = rpc::loggable(request);
BEAST_EXPECT(rendered.size() == rpc::kMaxLoggedChars);
BEAST_EXPECT(rendered.contains(kMasked));
BEAST_EXPECT(!rendered.contains(kSensitive));
// A short request is not padded.
json::Value small;
small[jss::seed] = kSensitive;
BEAST_EXPECT(rpc::loggable(small) == to_string(rpc::maskSecrets(small)));
// A value with no credential is the serialized value itself, cut at the cap.
json::Value plain;
plain[jss::account] = "rSomeAccount";
plain["zfiller"] = std::string(2 * rpc::kMaxLoggedChars, 'z');
BEAST_EXPECT(rpc::loggable(plain) == to_string(plain).substr(0, rpc::kMaxLoggedChars));
BEAST_EXPECT(rpc::loggable(small[jss::seed]) == to_string(small[jss::seed]));
}
/**
* A keygen reply is rendered for the log with no key in it.
*
* Every field of each reply is checked, not only the names on the list, so
* a field the list is missing fails here. Only the fields a client may read
* in public are allowed through.
*/
void
testKeygenRepliesAreMasked()
{
testcase("A keygen reply is logged with every key masked");
static constexpr std::array<std::string_view, 6> kPublicFields{
"account_id",
"key_type",
"public_key",
"public_key_hex",
"status",
"validation_public_key",
};
jtx::Env env{*this};
for (auto const command : {"wallet_propose", "validation_create"})
{
auto const reply = env.rpc(command);
auto const& result = reply[jss::result];
BEAST_EXPECT(result[jss::status] == "success");
auto const rendered = rpc::loggable(reply);
for (auto const& name : result.getMemberNames())
{
if (std::ranges::find(kPublicFields, name) != kPublicFields.end())
continue;
auto const& value = result[name];
BEAST_EXPECT(value.isString() && !value.asString().empty());
BEAST_EXPECTS(!rendered.contains(value.asString()), command + (": " + name));
}
}
}
void
run() override
{
testEveryCredentialField();
testNonCredentialsSurvive();
testNamesAreMatchedExactly();
testNesting();
testCredentialIsNotDescendedInto();
testNonStringCredentials();
testValuesWithoutMembers();
testRequestIsNotModified();
testHasSecret();
testLoggable();
testKeygenRepliesAreMasked();
}
};
BEAST_DEFINE_TESTSUITE(MaskSecrets, rpc, xrpl);
} // namespace xrpl::test

View File

@@ -328,6 +328,21 @@ class Simulate_test : public beast::unit_test::Suite
resp[jss::result][jss::error].toStyledString());
BEAST_EXPECT(resp[jss::result][jss::error_message] == "Invalid field 'tx.Account'.");
}
{
// A non-string `Account`, which no earlier check rejects: the `tx_json` arm validates
// only that it is an object, and the check above only that `Account` is present.
json::Value params;
json::Value txJson = json::ValueType::Object;
txJson[jss::TransactionType] = jss::AccountSet;
txJson[jss::Account] = 123;
params[jss::tx_json] = txJson;
auto const resp = env.rpc("json", "simulate", to_string(params));
BEAST_EXPECTS(
resp[jss::result][jss::error] == "invalidParams",
resp[jss::result][jss::error].toStyledString());
BEAST_EXPECT(resp[jss::result][jss::error_message] == "Invalid field 'tx.Account'.");
}
{
// Account doesn't exist for Sequence autofill
json::Value params;

View File

@@ -18,6 +18,7 @@
#include <xrpl/protocol/jss.h>
#include <memory>
#include <source_location>
#include <stdexcept>
#include <string>
@@ -25,6 +26,45 @@ namespace xrpl {
class TransactionEntry_test : public beast::unit_test::Suite
{
/**
* Asserts the reply carries the whole error, not just the token.
*
* @param result The reply's payload.
* @param token The `error` token expected.
* @param code The `error_code` expected.
* @param message The `error_message` expected.
* @param location The caller, reported when an assertion fails.
*/
void
checkCodedError(
json::Value const& result,
std::string const& token,
ErrorCodeI code,
std::string const& message,
std::source_location const location = std::source_location::current())
{
auto const at = std::to_string(location.line());
BEAST_EXPECTS(result[jss::error] == token, at);
BEAST_EXPECTS(result[jss::error_code] == code, at);
BEAST_EXPECTS(result[jss::error_message] == message, at);
BEAST_EXPECTS(result[jss::status] == "error", at);
}
/**
* Wire values pinned as literals, so reassigning a code fails here.
*/
void
testErrorCodeValues()
{
testcase("Error code values are stable");
BEAST_EXPECT(static_cast<int>(RpcFieldNotFoundTransaction) == 104);
BEAST_EXPECT(static_cast<int>(RpcNotYetImplemented) == 105);
BEAST_EXPECT(static_cast<int>(RpcTransactionNotFound) == 106);
BEAST_EXPECT(static_cast<int>(RpcMalformedRequest) == 107);
}
void
testBadInput()
{
@@ -38,8 +78,12 @@ class TransactionEntry_test : public beast::unit_test::Suite
{
// no params
auto const result = env.client().invoke("transaction_entry", {})[jss::result];
BEAST_EXPECT(result[jss::error] == "fieldNotFoundTransaction");
BEAST_EXPECT(result[jss::status] == "error");
// The message names the missing field rather than the table's default.
checkCodedError(
result,
"fieldNotFoundTransaction",
RpcFieldNotFoundTransaction,
"Missing field 'tx_hash'.");
}
{
@@ -55,8 +99,8 @@ class TransactionEntry_test : public beast::unit_test::Suite
params[jss::ledger] = "current";
params[jss::tx_hash] = "DEADBEEF";
auto const result = env.client().invoke("transaction_entry", params)[jss::result];
BEAST_EXPECT(result[jss::error] == "notYetImplemented");
BEAST_EXPECT(result[jss::status] == "error");
checkCodedError(
result, "notYetImplemented", RpcNotYetImplemented, "Not yet implemented.");
}
{
@@ -65,8 +109,8 @@ class TransactionEntry_test : public beast::unit_test::Suite
params[jss::tx_hash] =
"E2FE8D4AF3FCC3944DDF6CD8CDDC5E3F0AD50863EF8919AFEF10CB6408CD4D05";
auto const result = env.client().invoke("transaction_entry", params)[jss::result];
BEAST_EXPECT(result[jss::error] == "notYetImplemented");
BEAST_EXPECT(result[jss::status] == "error");
checkCodedError(
result, "notYetImplemented", RpcNotYetImplemented, "Not yet implemented.");
BEAST_EXPECT(result.isMember(jss::ledger_current_index));
BEAST_EXPECT(!result.isMember(jss::ledger_hash));
BEAST_EXPECT(result[jss::validated] == false);
@@ -78,18 +122,19 @@ class TransactionEntry_test : public beast::unit_test::Suite
params[jss::tx_hash] = "DEADBEEF";
auto const result = env.client().invoke("transaction_entry", params)[jss::result];
BEAST_EXPECT(!result[jss::ledger_hash].asString().empty());
BEAST_EXPECT(result[jss::error] == "malformedRequest");
BEAST_EXPECT(result[jss::status] == "error");
checkCodedError(
result, "malformedRequest", RpcMalformedRequest, "Request is malformed.");
}
// A `tx_hash` that is not a string is malformed, the same as one that is not hex.
for (auto const type : {json::ValueType::Object, json::ValueType::Array})
{
json::Value params{json::ValueType::Object};
params[jss::ledger] = "closed";
params[jss::tx_hash] = json::Value{type};
auto const result = env.client().invoke("transaction_entry", params)[jss::result];
BEAST_EXPECT(result[jss::error] == "malformedRequest");
BEAST_EXPECT(result[jss::status] == "error");
checkCodedError(
result, "malformedRequest", RpcMalformedRequest, "Request is malformed.");
}
std::string const txHash{
@@ -150,8 +195,11 @@ class TransactionEntry_test : public beast::unit_test::Suite
// Valid structure, but transaction not found.
json::Value const result{env.rpc("transaction_entry", txHash, "closed")};
BEAST_EXPECT(!result[jss::result][jss::ledger_hash].asString().empty());
BEAST_EXPECT(result[jss::result][jss::error] == "transactionNotFound");
BEAST_EXPECT(result[jss::result][jss::status] == "error");
checkCodedError(
result[jss::result],
"transactionNotFound",
RpcTransactionNotFound,
"Transaction not found.");
}
}
@@ -374,6 +422,7 @@ public:
void
run() override
{
testErrorCodeValues();
testBadInput();
forAllApiVersions([this](unsigned apiVersion) { testRequest(apiVersion); });
}

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,71 @@
#include <xrpl/protocol/ErrorCodes.h>
#include <gtest/gtest.h>
#include <set>
#include <type_traits>
using namespace xrpl;
// A row cannot be written without a status, so no row can default to 200 again.
static_assert(!std::is_constructible_v<rpc::ErrorInfo, ErrorCodeI, char const*, char const*>);
namespace {
/**
* The numbers between `RpcBadSyntax` and `RpcLast` that have no row in the
* error table: those no enumerator uses, and `RpcReportingUnsupported` (91),
* the one enumerator the table does not list.
*/
std::set<int> const kGaps{5, 8, 20, 24, 25, 26, 27, 28, 34, 38, 39, 54, 55, 56,
59, 60, 61, 81, 82, 83, 84, 85, 86, 87, 88, 89, 90, 91};
} // namespace
TEST(ErrorCodes, table_gaps_report_the_unknown_placeholder)
{
// Codes absent from the table report the placeholder, so a scan by code must skip them.
auto const& gap = rpc::getErrorInfo(static_cast<ErrorCodeI>(5));
EXPECT_EQ(gap.code, RpcUnknown);
EXPECT_STREQ(gap.token.cStr(), "unknown");
auto const& real = rpc::getErrorInfo(RpcInvalidParams);
EXPECT_EQ(real.code, RpcInvalidParams);
EXPECT_STREQ(real.token.cStr(), "invalidParams");
}
TEST(ErrorCodes, exactly_the_listed_codes_have_no_row)
{
// The gap set is written out by hand, so an enumerator added without a row fails here, where a
// test asking the table which codes it knows would take the missing row for a gap.
for (int code = RpcBadSyntax; code <= RpcLast; ++code)
{
bool const isGap = rpc::getErrorInfo(static_cast<ErrorCodeI>(code)).code == RpcUnknown;
EXPECT_EQ(isGap, kGaps.contains(code)) << "code " << code;
}
}
TEST(ErrorCodes, every_code_names_an_http_status)
{
// Written out here rather than read from the row: a test reading the row production reads
// cannot tell whether the row is right.
EXPECT_EQ(rpc::errorCodeHttpStatus(RpcActMalformed), 400);
EXPECT_EQ(rpc::errorCodeHttpStatus(RpcActNotFound), 404);
EXPECT_EQ(rpc::errorCodeHttpStatus(RpcAlreadyMultisig), 400);
EXPECT_EQ(rpc::errorCodeHttpStatus(RpcAlreadySingleSig), 400);
// Every row names a status of its own. A code with no row reports the placeholder's, which the
// default constructor fixes at 200.
for (int code = RpcBadSyntax; code <= RpcLast; ++code)
{
auto const status = rpc::errorCodeHttpStatus(static_cast<ErrorCodeI>(code));
if (kGaps.contains(code))
{
EXPECT_EQ(status, 200) << "code " << code;
}
else
{
EXPECT_NE(status, 200) << "code " << code;
}
}
}

View File

@@ -0,0 +1,105 @@
#include <xrpl/server/detail/JSONRPCUtil.h>
#include <xrpl/beast/utility/Journal.h>
#include <xrpl/protocol/ErrorCodes.h>
#include <gtest/gtest.h>
#include <set>
#include <string>
#include <string_view>
using namespace xrpl;
namespace {
/**
* The reply httpReply writes, collected as one string.
*
* @param status The HTTP status to write a reply for.
* @return The whole reply, headers and body.
*/
std::string
reply(int status)
{
std::string out;
beast::Journal const journal{beast::Journal::getNullSink()};
httpReply(status, "{}", [&out](std::string_view s) { out += s; }, journal);
return out;
}
/**
* The reply's status line, without the trailing CRLF.
*
* @param reply A whole HTTP reply.
* @return The first line, or the whole reply when it holds no CRLF.
*/
std::string_view
statusLine(std::string const& reply)
{
auto const end = reply.find("\r\n");
return std::string_view{reply}.substr(0, end == std::string::npos ? reply.size() : end);
}
} // namespace
TEST(JSONRPCUtil, status_line_names_the_status)
{
// Every status this server sends but the two the last test names. The phrase comes from the
// registry but for the two below.
EXPECT_EQ(statusLine(reply(200)), "HTTP/1.1 200 OK");
EXPECT_EQ(statusLine(reply(202)), "HTTP/1.1 202 Accepted");
EXPECT_EQ(statusLine(reply(400)), "HTTP/1.1 400 Bad Request");
EXPECT_EQ(statusLine(reply(403)), "HTTP/1.1 403 Forbidden");
EXPECT_EQ(statusLine(reply(404)), "HTTP/1.1 404 Not Found");
EXPECT_EQ(statusLine(reply(405)), "HTTP/1.1 405 Method Not Allowed");
EXPECT_EQ(statusLine(reply(429)), "HTTP/1.1 429 Too Many Requests");
EXPECT_EQ(statusLine(reply(500)), "HTTP/1.1 500 Internal Server Error");
EXPECT_EQ(statusLine(reply(501)), "HTTP/1.1 501 Not Implemented");
// The two whose phrase is this server's own, not the registry's.
EXPECT_EQ(statusLine(reply(401)), "HTTP/1.1 401 Authorization Required");
EXPECT_EQ(statusLine(reply(503)), "HTTP/1.1 503 Server is overloaded");
}
TEST(JSONRPCUtil, every_status_the_error_table_names_gets_a_status_line)
{
// httpReply sees a status, not the table, so only this can check every status the table names.
std::set<int> statuses;
for (int i = RpcBadSyntax; i <= RpcLast; ++i)
{
auto const& info = rpc::getErrorInfo(static_cast<ErrorCodeI>(i));
// Gaps in the table name no error, so they report no status of their own.
if (info.code == RpcUnknown)
continue;
statuses.insert(info.httpStatus);
}
EXPECT_FALSE(statuses.empty());
for (int const status : statuses)
{
auto const line = std::string{statusLine(reply(status))};
auto const expectedPrefix = "HTTP/1.1 " + std::to_string(status) + " ";
EXPECT_TRUE(line.starts_with(expectedPrefix)) << "status: " << status << ", line: " << line;
// A placeholder phrase means the table names something that is not a status.
EXPECT_GT(line.size(), expectedPrefix.size()) << "status: " << status;
EXPECT_EQ(line.find("unknown-status"), std::string::npos) << "status: " << status;
}
}
TEST(JSONRPCUtil, statuses_without_a_case_take_the_registry_phrase)
{
// The two statuses the error table names and the switch spells no case for.
EXPECT_EQ(rpc::errorCodeHttpStatus(RpcHighFee), 402);
EXPECT_EQ(statusLine(reply(402)), "HTTP/1.1 402 Payment Required");
EXPECT_EQ(rpc::errorCodeHttpStatus(RpcDbDeserialization), 502);
EXPECT_EQ(statusLine(reply(502)), "HTTP/1.1 502 Bad Gateway");
// A number the registry does not know still gets a line, with the placeholder phrase the table
// test above refuses.
EXPECT_EQ(statusLine(reply(999)), "HTTP/1.1 999 <unknown-status>");
}

View File

@@ -36,6 +36,7 @@
#include <xrpld/rpc/Role.h>
#include <xrpld/rpc/ServerHandler.h>
#include <xrpld/rpc/detail/Handler.h>
#include <xrpld/rpc/detail/MaskSecrets.h>
#include <xrpld/rpc/detail/PathRequestManager.h>
#include <xrpld/rpc/detail/Pathfinder.h>
#include <xrpld/shamap/NodeFamily.h>
@@ -1473,7 +1474,7 @@ ApplicationImp::setup(boost::program_options::variables_map const& cmdline)
if (!config_->quiet())
{
JLOG(journal_.fatal()) << "Startup RPC: " << jvCommand << std::endl;
JLOG(journal_.fatal()) << "Startup RPC: " << rpc::loggable(jvCommand) << std::endl;
}
resource::Charge loadType = resource::kFeeReferenceRpc;
@@ -1496,7 +1497,7 @@ ApplicationImp::setup(boost::program_options::variables_map const& cmdline)
if (!config_->quiet())
{
JLOG(journal_.fatal()) << "Result: " << jvResult << std::endl;
JLOG(journal_.fatal()) << "Result: " << rpc::loggable(jvResult) << std::endl;
}
}

View File

@@ -171,6 +171,18 @@ public:
void
onRequest(Session& session);
/**
* Receives one WebSocket frame.
*
* A frame that exceeds the request size limit, does not parse or is not
* an object is answered here with `jsonInvalid` and the frame's `size`;
* its body is never echoed, since an unparsed body has no fields to mask.
* Any other frame is posted to the job queue and answered from
* processSession.
*
* @param session The WebSocket session the frame arrived on.
* @param buffers The frame's bytes.
*/
void
onWSMessage(
std::shared_ptr<WSSession> session,
@@ -183,15 +195,54 @@ public:
onStopped(Server&);
private:
/**
* Serves one parsed WebSocket request.
*
* Closes the connection when its resource balance is past the drop
* threshold. Otherwise checks the API version and the `command` and
* `method` fields, dispatches through rpc::doCommand, charges the
* session's consumer, and shapes the reply as a `response`, echoing the
* masked request on an error.
*
* @param session The session the request arrived on.
* @param coro The coroutine the request runs on.
* @param jv The parsed request.
* @return The reply to send.
*/
json::Value
processSession(
std::shared_ptr<WSSession> const& session,
std::shared_ptr<JobQueue::Coro> const& coro,
json::Value const& jv);
/**
* Serves one HTTP request on a coroutine: hands the body, the client
* address and the forwarding headers to processRequest, then completes
* or closes the session as its keep-alive header asks.
*
* @param session The HTTP session the request arrived on.
* @param coro The coroutine the request runs on.
*/
void
processSession(std::shared_ptr<Session> const&, std::shared_ptr<JobQueue::Coro> coro);
processSession(std::shared_ptr<Session> const& session, std::shared_ptr<JobQueue::Coro> coro);
/**
* Serves one HTTP body: parses it, answers a malformed or unauthorized
* request with a plain-text status, serves a `method: "batch"` body entry
* by entry, dispatches each request through rpc::doCommand, and writes
* the reply with its HTTP status. An error reply echoes the masked
* request.
*
* @param port The port the request arrived on, for its role and limits.
* @param request The raw body.
* @param remoteIPAddress The client address, for resource accounting and
* the role.
* @param output Where the reply bytes are written.
* @param coro The coroutine the request runs on.
* @param forwardedFor The `X-Forwarded-For` header, when the port trusts
* a proxy.
* @param user The `X-User` header.
*/
void
processRequest(
Port const& port,

View File

@@ -0,0 +1,88 @@
#include <xrpld/rpc/detail/MaskSecrets.h>
#include <xrpl/json/json_value.h>
#include <xrpl/json/to_string.h>
#include <algorithm>
#include <string>
#include <string_view>
namespace xrpl::rpc {
namespace {
/**
* Reports whether @p name is one of kCredentialFields.
*
* An array element's memberName is empty, which no credential is spelled as,
* so an element is never a credential itself and is descended into.
*
* @param name The member name to look up.
* @return True if @p name is a credential-bearing field.
*/
bool
isCredential(std::string_view name)
{
return !name.empty() && std::ranges::find(kCredentialFields, name) != kCredentialFields.end();
}
/**
* Replaces every credential-bearing field of @p value in place, at every depth.
*
* @param value The object or array to mask. Any other value is left alone.
*/
void
maskInPlace(json::Value& value)
{
if (!value.isObject() && !value.isArray())
return;
for (auto it = value.begin(); it != value.end(); ++it)
{
// A credential is replaced whatever it holds, so it is not descended into.
if (isCredential(it.memberName()))
{
*it = json::Value{"<masked>"};
}
else
{
maskInPlace(*it);
}
}
}
} // namespace
bool
hasSecret(json::Value const& value)
{
if (!value.isObject() && !value.isArray())
return false;
for (auto it = value.begin(); it != value.end(); ++it)
{
if (isCredential(it.memberName()) || hasSecret(*it))
return true;
}
return false;
}
json::Value
maskSecrets(json::Value const& request)
{
auto masked = request;
maskInPlace(masked);
return masked;
}
std::string
loggable(json::Value const& value)
{
// The copy the mask takes is paid only when there is a credential to replace.
auto text = hasSecret(value) ? to_string(maskSecrets(value)) : to_string(value);
if (text.size() > kMaxLoggedChars)
text.resize(kMaxLoggedChars);
return text;
}
} // namespace xrpl::rpc

View File

@@ -0,0 +1,99 @@
#pragma once
#include <xrpl/json/json_value.h>
#include <array>
#include <cstddef>
#include <string>
#include <string_view>
namespace xrpl::rpc {
/**
* Fields that carry a credential, in a request or in a reply.
*
* Literals rather than jss entries, since not every one has a jss entry.
*
* `username` and `password` are `subscribe`'s deprecated spellings of
* `url_username` and `url_password`, which is why a name identifying rather
* than authenticating is on the list. The `master_` and `validation_` names
* come from `wallet_propose` and `validation_create` replies, and a reply is
* logged like a request. `master_key` is also the public key that
* `validator_info` and the `manifests` and `validations` streams report, and
* it is masked with the rest.
*/
inline constexpr std::array<std::string_view, 16> kCredentialFields{
"admin_password",
"admin_user",
"master_key",
"master_seed",
"master_seed_hex",
"passphrase",
"password",
"secret",
"seed",
"seed_hex",
"url_password",
"url_username",
"username",
"validation_key",
"validation_private_key",
"validation_seed",
};
/**
* How much of a request or a reply a log line carries.
*
* A client chooses the size of what it sends, so nothing it cannot choose
* bounds the length.
*/
inline constexpr std::size_t kMaxLoggedChars = 10000;
/**
* Returns a copy of @p request with every credential-bearing field replaced by
* a placeholder.
*
* Apply to every request echoed back to a caller. Masks at every depth, since
* the JSON-RPC transport nests a credential inside `params` and a batch nests
* one request per entry. Recursion is bounded by json::Reader::kNestLimit.
*
* @param request The request to mask.
* @return The masked copy.
*/
[[nodiscard]] json::Value
maskSecrets(json::Value const& request);
/**
* Reports whether @p value carries a credential-bearing field at any depth.
*
* Walks objects and arrays without copying and stops at the first field named
* in kCredentialFields, so a caller pays for masking only when there is
* something to mask. A value with no members carries none.
*
* @param value The request or reply to inspect.
* @return True if a credential-bearing field is present at any depth.
*/
[[nodiscard]] bool
hasSecret(json::Value const& value);
/**
* Renders @p value for a log line: masked when it carries a credential, then
* truncated to kMaxLoggedChars.
*
* Every site that writes a request or a reply body to the log goes through
* this. A value with no credential is serialized as it is, so the copy the
* mask takes is paid only when hasSecret() reports one.
*
* Call it inside the JLOG argument and never before the macro: that argument is
* evaluated only when the sink is active, so hoisting the call puts the walk
* and the serialization on every request.
*
* Truncation is by bytes, so a multi-byte character can be split.
*
* @param value The request or reply to render.
* @return The masked, truncated text.
*/
[[nodiscard]] std::string
loggable(json::Value const& value);
} // namespace xrpl::rpc

View File

@@ -3,6 +3,7 @@
#include <xrpld/core/Config.h>
#include <xrpld/rpc/MethodNames.h>
#include <xrpld/rpc/ServerHandler.h>
#include <xrpld/rpc/detail/MaskSecrets.h>
#include <xrpl/basics/ByteUtilities.h>
#include <xrpl/basics/Log.h>
@@ -615,21 +616,32 @@ private:
return rpcError(RpcInvalidParams);
}
// json <command> <json>
/**
* Parses the `json <command> <json>` form: the second argument is parsed
* as the request and the first becomes its `method`. The request is
* logged masked once parsed; the unparsed text never is.
*
* @param jvParams The command name and the JSON text.
* @return The request, or `invalidParams` when the text does not parse
* to an object.
*/
json::Value
parseJson(json::Value const& jvParams)
{
json::Reader reader;
json::Value jvRequest;
// The command name cannot carry a credential, so it logs whether the JSON parses or not.
JLOG(j_.trace()) << "RPC method: " << jvParams[0u];
JLOG(j_.trace()) << "RPC json: " << jvParams[1u];
if (reader.parse(jvParams[1u].asString(), jvRequest))
{
if (!jvRequest.isObjectOrNull())
return rpcError(RpcInvalidParams);
// Logged only once parsed, so a signing secret among the members can be masked.
JLOG(j_.trace()) << "RPC json: " << rpc::loggable(jvRequest);
jvRequest[jss::method] = jvParams[0u];
return jvRequest;
@@ -1021,7 +1033,14 @@ private:
return jvRequest;
}
// ripple_path_find <json> [<ledger>]
/**
* Parses the `ripple_path_find <json> [<ledger>]` form: the first
* argument is parsed as the request and logged masked once parsed, the
* optional second names the ledger.
*
* @param jvParams The JSON text and, optionally, the ledger.
* @return The request, or `invalidParams` when the text does not parse.
*/
json::Value
parseRipplePathFind(json::Value const& jvParams)
{
@@ -1029,10 +1048,12 @@ private:
json::Value jvRequest{json::ValueType::Object};
bool const bLedger = 2 == jvParams.size();
JLOG(j_.trace()) << "RPC json: " << jvParams[0u];
if (reader.parse(jvParams[0u].asString(), jvRequest))
{
// The JSON is logged only once parsed, so a signing secret among the named members can
// be masked. Unparsed it is a bare string with no members to name.
JLOG(j_.trace()) << "RPC json: " << rpc::loggable(jvRequest);
if (bLedger)
{
jvParseLedger(jvRequest, jvParams[1u].asString());
@@ -1761,11 +1782,7 @@ public:
json::Value
parseCommand(std::string_view strMethod, json::Value const& jvParams, bool allowAnyCommand)
{
if (auto stream = j_.trace())
{
stream << "Method: '" << strMethod << "'";
stream << "Params: " << jvParams;
}
JLOG(j_.trace()) << "Method: '" << strMethod << "'";
auto const found = std::ranges::lower_bound(kSortedCommands, strMethod, {}, &Command::name);
@@ -1872,15 +1889,26 @@ struct RPCCallImp
"process.");
}
// Parse reply
JLOG(j.debug()) << "RPC reply: " << strData << std::endl;
// Parse reply. A plain text body is a rejection, which carries no field a credential
// could sit in, so it is logged as it is, capped at kMaxLoggedChars.
if (strData.starts_with("Unable to parse request") ||
strData.starts_with(jss::invalid_API_version.cStr()))
{
JLOG(j.debug()) << "RPC reply: "
<< std::string_view{strData}.substr(0, rpc::kMaxLoggedChars);
Throw<RequestNotParsable>(strData);
}
json::Reader reader;
json::Value jvReply;
if (!reader.parse(strData, jvReply))
{
JLOG(j.debug()) << "RPC reply: "
<< std::string_view{strData}.substr(0, rpc::kMaxLoggedChars);
Throw<std::runtime_error>("couldn't parse reply from server");
}
// Logged once parsed, masked: `validation_create` and `wallet_propose` answer with a
// private key, which the fallback scrubber in Log.cpp does not know by every name.
JLOG(j.debug()) << "RPC reply: " << rpc::loggable(jvReply);
if (!jvReply)
Throw<std::runtime_error>("expected reply to have result, error and id properties");
@@ -1922,7 +1950,16 @@ commandLineMethodNames()
return RPCParser::methodNames();
}
// Used internally by rpcClient.
/**
* Translates command line arguments into the request the client sends.
*
* @param args The method name followed by its positional arguments.
* @param retParams Receives the arguments as `method` and `params`, the form
* `rpc` echoes on an error.
* @param apiVersion The `api_version` stamped on each request naming none.
* @param j The journal the built request is logged to, masked.
* @return The request, an array of requests, or the parser's error object.
*/
json::Value
rpcCmdToJson(
std::vector<std::string> const& args,
@@ -1962,12 +1999,27 @@ rpcCmdToJson(
std::for_each(jvRequest.begin(), jvRequest.end(), insertApiVersion);
}
JLOG(j.trace()) << "RPC Request: " << jvRequest << std::endl;
// `sign` and `submit` put the signing secret in the request the command line built.
JLOG(j.trace()) << "RPC Request: " << rpc::loggable(jvRequest) << std::endl;
return jvRequest;
}
//------------------------------------------------------------------------------
/**
* Runs one command line command against the configured server.
*
* Builds the request, adds the admin credentials from the config, sends it
* over HTTP and unwraps the result. On an error the output also carries the
* invocation as `rpc` and the request as `request_sent`, masked.
*
* @param args The method name followed by its arguments.
* @param config The client configuration naming the server and credentials.
* @param logs The log manager.
* @param apiVersion The `api_version` to request.
* @param headers Extra HTTP headers to send.
* @return The exit code and the output to print.
*/
std::pair<int, json::Value>
rpcClient(
std::vector<std::string> const& args,
@@ -2079,7 +2131,9 @@ rpcClient(
if (jvOutput.isMember(jss::error))
{
jvOutput["rpc"] = jvRpc; // How the command was seen as method + params.
jvOutput["request_sent"] = jvRequest; // How the command was translated.
// Carries the config's `admin_password` and prints to stdout, so it is masked.
// `jvRpc` above is positional, so masking by member name does not reach it.
jvOutput["request_sent"] = rpc::maskSecrets(jvRequest);
}
}

View File

@@ -6,6 +6,7 @@
#include <xrpld/rpc/Context.h>
#include <xrpld/rpc/Role.h>
#include <xrpld/rpc/detail/Handler.h>
#include <xrpld/rpc/detail/MaskSecrets.h>
#include <xrpld/rpc/detail/Tuning.h>
#include <xrpl/basics/Log.h>
@@ -136,7 +137,7 @@ fillHandler(JsonContext& context, Handler const*& result)
: context.params[jss::method].asString();
JLOG(context.j.trace()) << "COMMAND:" << strCommand;
JLOG(context.j.trace()) << "REQUEST:" << context.params;
JLOG(context.j.trace()) << "REQUEST:" << loggable(context.params);
auto handler = getHandler(context.apiVersion, context.app.config().betaRpcApi, strCommand);
if (handler == nullptr)

View File

@@ -1,6 +1,7 @@
#include <xrpld/rpc/RPCSub.h>
#include <xrpld/rpc/RPCCall.h>
#include <xrpld/rpc/detail/MaskSecrets.h>
#include <xrpl/basics/Log.h>
#include <xrpl/basics/StringUtilities.h>
@@ -87,7 +88,7 @@ public:
std::scoped_lock const sl(lock_);
auto jm = broadcast ? j_.debug() : j_.info();
JLOG(jm) << "rpc_call::fromNetwork push: " << jvObj;
JLOG(jm) << "rpc_call::fromNetwork push: " << rpc::loggable(jvObj);
deque_.emplace_back(seq_++, jvObj);

View File

@@ -4,6 +4,7 @@
#include <xrpld/overlay/Overlay.h>
#include <xrpld/rpc/RPCHandler.h>
#include <xrpld/rpc/Role.h>
#include <xrpld/rpc/detail/MaskSecrets.h>
#include <xrpld/rpc/detail/Tuning.h>
#include <xrpld/rpc/detail/WSInfoSub.h>
@@ -28,6 +29,7 @@
#include <xrpl/protocol/ApiVersion.h>
#include <xrpl/protocol/BuildInfo.h>
#include <xrpl/protocol/ErrorCodes.h>
#include <xrpl/protocol/JsonRpc.h>
#include <xrpl/protocol/RPCErr.h>
#include <xrpl/protocol/SystemParameters.h>
#include <xrpl/protocol/jss.h>
@@ -60,10 +62,13 @@
#include <algorithm>
#include <cctype>
#include <chrono>
#include <cstddef>
#include <exception>
#include <limits>
#include <map>
#include <memory>
#include <mutex>
#include <optional>
#include <ostream>
#include <string>
#include <string_view>
@@ -339,10 +344,13 @@ ServerHandler::onWSMessage(
auto const size = boost::asio::buffer_size(buffers);
if (size > rpc::tuning::kMaxRequestSize || !json::Reader{}.parse(jv, buffers) || !jv.isObject())
{
// An unparsed body cannot be masked field-wise, so its size goes instead of its content.
// Clamped rather than narrowed: json has no integer wider than 32 bits.
json::Value jvResult(json::ValueType::Object);
jvResult[jss::type] = jss::error;
jvResult[jss::error] = "jsonInvalid";
jvResult[jss::value] = buffersToString(buffers);
jvResult[jss::size] =
json::UInt(std::min<std::size_t>(size, std::numeric_limits<json::UInt>::max()));
boost::beast::multi_buffer sb;
json::stream(jvResult, [&sb](auto const p, auto const n) {
sb.commit(boost::asio::buffer_copy(sb.prepare(n), boost::asio::buffer(p, n)));
@@ -353,7 +361,7 @@ ServerHandler::onWSMessage(
return;
}
JLOG(journal_.trace()) << "Websocket received '" << jv << "'";
JLOG(journal_.trace()) << "Websocket received '" << rpc::loggable(jv) << "'";
auto const postResult = jobQueue_.postCoro(
JtClientWebsocket,
@@ -391,22 +399,35 @@ ServerHandler::onStopped(Server&)
//------------------------------------------------------------------------------
/**
* Logs how long a request took.
*
* A slow request is reported at warn from one second and at error from ten,
* with the duration only. The request is logged at debug, since it is client
* text.
*
* @param request The request the duration belongs to.
* @param duration How long processing it took.
* @param journal Where the line is written.
*/
template <class T>
void
logDuration(json::Value const& request, T const& duration, beast::Journal& journal)
{
using namespace std::chrono_literals;
auto const level = [&] {
if (duration >= 10s)
return journal.error();
if (duration >= 1s)
return journal.warn();
return journal.debug();
}();
auto const micros = std::chrono::duration_cast<std::chrono::microseconds>(duration).count();
JLOG(level) << "RPC request processing duration = "
<< std::chrono::duration_cast<std::chrono::microseconds>(duration).count()
<< " microseconds. request = " << request;
if (duration >= 1s)
{
auto const slow = duration >= 10s ? journal.error() : journal.warn();
JLOG(slow) << "RPC request processing duration = " << micros << " microseconds.";
}
if (auto const stream = journal.debug())
{
stream << "RPC request processing duration = " << micros
<< " microseconds. request = " << rpc::loggable(request);
}
}
json::Value
@@ -441,7 +462,7 @@ ServerHandler::processSession(
jr[jss::status] = jss::error;
jr[jss::error] = apiVersion == rpc::kApiInvalidVersion ? jss::invalid_API_version
: jss::missingCommand;
jr[jss::request] = jv;
jr[jss::request] = rpc::maskSecrets(jv);
if (jv.isMember(jss::id))
jr[jss::id] = jv[jss::id];
if (jv.isMember(jss::jsonrpc))
@@ -494,11 +515,9 @@ ServerHandler::processSession(
}
catch (std::exception const& ex)
{
// LCOV_EXCL_START
jr[jss::result] = rpc::makeError(RpcInternal);
JLOG(journal_.error()) << "Exception while processing WS: " << ex.what() << "\n"
<< "Input JSON: " << json::Compact{json::Value{jv}};
// LCOV_EXCL_STOP
<< "Input JSON: " << rpc::loggable(jv);
}
is->getConsumer().charge(loadType);
@@ -515,21 +534,7 @@ ServerHandler::processSession(
jr = jr[jss::result];
jr[jss::status] = jss::error;
auto rq = jv;
if (rq.isObject())
{
if (rq.isMember(jss::passphrase.cStr()))
rq[jss::passphrase.cStr()] = "<masked>";
if (rq.isMember(jss::secret.cStr()))
rq[jss::secret.cStr()] = "<masked>";
if (rq.isMember(jss::seed.cStr()))
rq[jss::seed.cStr()] = "<masked>";
if (rq.isMember(jss::seed_hex.cStr()))
rq[jss::seed_hex.cStr()] = "<masked>";
}
jr[jss::request] = rq;
jr[jss::request] = rpc::maskSecrets(jv);
}
else
{
@@ -590,10 +595,143 @@ makeJsonError(json::Int code, json::Value&& message)
return r;
}
constexpr json::Int kMethodNotFound = -32601;
constexpr json::Int kServerOverloaded = -32604;
constexpr json::Int kForbidden = -32605;
constexpr json::Int kWrongVersion = -32606;
// Version of the JSON-RPC reply envelope, selected by the `ripplerpc` request parameter. It shapes
// a completed result into a reply; no handler observes it.
enum class RpcVersion {
// Errors are returned under `result`, keyed by `error_message`, and echo the (secret-masked)
// request. HTTP status is always 200.
V1,
// Errors are returned under `error`, keyed by `message`, and the request is not echoed. HTTP
// status is always 200.
V2,
// As V2, but the error code selects a 4xx/5xx HTTP status.
V3,
};
constexpr RpcVersion kRpcVersionIfUnspecified = RpcVersion::V1;
/**
* Maps a `ripplerpc` value onto the envelope version it selects.
*
* The value is unauthenticated, so anything but an exact match is refused.
*
* @param value The `ripplerpc` member, as sent.
* @return The envelope version, or nullopt for the caller to reject.
*/
static std::optional<RpcVersion>
rpcVersion(std::string_view value)
{
if (value == rpc::kRippleRpcVersion1)
return RpcVersion::V1;
if (value == rpc::kRippleRpcVersion2)
return RpcVersion::V2;
if (value == rpc::kRippleRpcVersion3)
return RpcVersion::V3;
return std::nullopt;
}
/**
* The HTTP status the `ripplerpc: "3.0"` envelope reports for @p code.
*
* The codes below answer 200, which is what a client calling `account_info`
* this way already reads. The list is closed: a code belongs on it only if it
* already answered a coded reply at this status.
*
* @param code The error code the reply reports.
* @return The HTTP status the reply is sent with.
*/
static int
legacyHttpStatus(ErrorCodeI code)
{
switch (code)
{
case RpcActMalformed:
case RpcActNotFound:
case RpcAlreadyMultisig:
case RpcAlreadySingleSig:
return 200;
default:
return rpc::errorCodeHttpStatus(code);
}
}
/**
* Shapes a handler @p result into the reply envelope for @p version, appending
* it to @p reply.
*
* @param version The envelope the reply takes.
* @param result A handler result, consumed.
* @param request The request's parameters, echoed on a version 1 error only,
* and where the `jsonrpc`, `ripplerpc` and `id` members are read.
* @param batch Whether to append to @p reply rather than assign it.
* @param reply The reply this writes.
* @param journal Where an error is logged.
* @return The HTTP status the reply is sent with. Only version 3 derives it
* from the error code; the others report 200. A batch discards it.
*/
static int
shapeReply(
RpcVersion version,
json::Value result,
json::Value const& request,
bool batch,
json::Value& reply,
beast::Journal journal)
{
json::Value r(json::ValueType::Object);
int status = 200;
if (!result.isMember(jss::error))
{
result[jss::status] = jss::success;
r[jss::result] = std::move(result);
}
else
{
// Read through a const reference: the non-const `operator[]` inserts a null member for an
// absent name, and the reply below is built out of `result`.
json::Value const& reported = result;
JLOG(journal.debug()) << "rpcError: " << reported[jss::error] << ": "
<< reported[jss::error_message];
if (version == RpcVersion::V3 && reported[jss::error_code].isInt())
status = legacyHttpStatus(static_cast<ErrorCodeI>(reported[jss::error_code].asInt()));
result[jss::status] = jss::error;
if (version == RpcVersion::V1)
{
result[jss::request] = rpc::maskSecrets(request);
r[jss::result] = std::move(result);
}
else
{
result[jss::code] = result[jss::error_code];
result[jss::message] = result[jss::error_message];
result.removeMember(jss::error_message);
r[jss::error] = std::move(result);
}
}
if (request.isMember(jss::jsonrpc))
r[jss::jsonrpc] = request[jss::jsonrpc];
if (request.isMember(jss::ripplerpc))
r[jss::ripplerpc] = request[jss::ripplerpc];
if (request.isMember(jss::id))
r[jss::id] = request[jss::id];
if (batch)
{
reply.append(std::move(r));
}
else
{
reply = std::move(r);
}
return status;
}
void
ServerHandler::processRequest(
@@ -638,16 +776,22 @@ ServerHandler::processRequest(
}
json::Value reply(batch ? json::ValueType::Array : json::ValueType::Object);
// Only a lone request selects the HTTP status: a batch may mix versions and reports each
// entry's outcome in its own reply, so the batch itself always succeeds.
int httpStatus = 200;
auto const start(std::chrono::high_resolution_clock::now());
for (unsigned i = 0; i < size; ++i)
{
json::Value const& jsonRPC = batch ? jsonOrig[jss::params][i] : jsonOrig;
// Only an entry of a batch can be a non-object; a lone request was checked before the loop.
// Inline rather than through `reject` below: an entry with no members carries the copy
// under `request` whatever a caller asks for.
if (!jsonRPC.isObject())
{
json::Value r(json::ValueType::Object);
r[jss::request] = jsonRPC;
r[jss::error] = makeJsonError(kMethodNotFound, "Method not found");
r[jss::request] = rpc::maskSecrets(jsonRPC);
r[jss::error] = makeJsonError(rpc::kJsonRpcMethodNotFound, "Method not found");
reply.append(r);
continue;
}
@@ -666,17 +810,45 @@ ServerHandler::processRequest(
apiVersion = rpc::getAPIVersionNumber(jsonRPC, app_.config().betaRpcApi);
}
// Answers a request rejected before it reaches a handler. A lone request receives the
// HTTP status and `message` as the whole body; a batch entry receives an error object
// beside a copy of the entry, one reply array having no other place to name the entry that
// failed. `wrapRequest` puts that copy under `request` instead.
//
// Returns whether the loop continues, which it does only for a batch.
auto const reject =
[&](int status, json::Int code, char const* message, bool wrapRequest = false) {
if (!batch)
{
httpReply(status, message, output, rpcJ);
return false;
}
json::Value r(json::ValueType::Object);
if (!wrapRequest)
{
r = rpc::maskSecrets(jsonRPC);
}
else
{
r[jss::request] = rpc::maskSecrets(jsonRPC);
}
r[jss::error] = makeJsonError(code, message);
reply.append(std::move(r));
return true;
};
if (apiVersion == rpc::kApiInvalidVersion)
{
if (!batch)
// An object-shaped rejection returns this entry under `request`, where a client
// correlating by `reply[i].request` finds it.
if (!reject(
400,
rpc::kJsonRpcWrongVersion,
jss::invalid_API_version.cStr(),
/*wrapRequest=*/true))
{
httpReply(400, jss::invalid_API_version.cStr(), output, rpcJ);
return;
}
json::Value r(json::ValueType::Object);
r[jss::request] = jsonRPC;
r[jss::error] = makeJsonError(kWrongVersion, jss::invalid_API_version.cStr());
reply.append(r);
continue;
}
@@ -700,54 +872,31 @@ ServerHandler::processRequest(
role = requestRole(required, port, json::ValueType::Object, remoteIPAddress, user);
}
resource::Consumer usage;
if (isUnlimited(role))
auto usage =
requestInboundEndpoint(resourceManager_, remoteIPAddress, role, user, forwardedFor);
// An overloaded server sheds the request without charging for it; disconnect() has already
// accounted for the load that got it here.
if (!isUnlimited(role) && usage.disconnect(journal_))
{
usage = resourceManager_.newUnlimitedEndpoint(remoteIPAddress);
}
else
{
usage = resourceManager_.newInboundEndpoint(
remoteIPAddress, role == Role::PROXY, forwardedFor);
if (usage.disconnect(journal_))
{
if (!batch)
{
httpReply(503, "Server is overloaded", output, rpcJ);
return;
}
json::Value r = jsonRPC;
r[jss::error] = makeJsonError(kServerOverloaded, "Server is overloaded");
reply.append(r);
continue;
}
if (!reject(503, rpc::kJsonRpcServerOverloaded, "Server is overloaded"))
return;
continue;
}
if (role == Role::FORBID)
{
usage.charge(resource::kFeeMalformedRpc);
if (!batch)
{
httpReply(403, "Forbidden", output, rpcJ);
if (!reject(403, rpc::kJsonRpcForbidden, "Forbidden"))
return;
}
json::Value r = jsonRPC;
r[jss::error] = makeJsonError(kForbidden, "Forbidden");
reply.append(r);
continue;
}
if (!jsonRPC.isMember(jss::method) || jsonRPC[jss::method].isNull())
{
usage.charge(resource::kFeeMalformedRpc);
if (!batch)
{
httpReply(400, "Null method", output, rpcJ);
if (!reject(400, rpc::kJsonRpcMethodNotFound, "Null method"))
return;
}
json::Value r = jsonRPC;
r[jss::error] = makeJsonError(kMethodNotFound, "Null method");
reply.append(r);
continue;
}
@@ -755,14 +904,8 @@ ServerHandler::processRequest(
if (!method.isString())
{
usage.charge(resource::kFeeMalformedRpc);
if (!batch)
{
httpReply(400, "method is not string", output, rpcJ);
if (!reject(400, rpc::kJsonRpcMethodNotFound, "method is not string"))
return;
}
json::Value r = jsonRPC;
r[jss::error] = makeJsonError(kMethodNotFound, "method is not string");
reply.append(r);
continue;
}
@@ -770,14 +913,8 @@ ServerHandler::processRequest(
if (strMethod.empty())
{
usage.charge(resource::kFeeMalformedRpc);
if (!batch)
{
httpReply(400, "method is empty", output, rpcJ);
if (!reject(400, rpc::kJsonRpcMethodNotFound, "method is empty"))
return;
}
json::Value r = jsonRPC;
r[jss::error] = makeJsonError(kMethodNotFound, "method is empty");
reply.append(r);
continue;
}
@@ -817,24 +954,29 @@ ServerHandler::processRequest(
params = jsonRPC;
}
std::string ripplerpc = "1.0";
RpcVersion envelope = kRpcVersionIfUnspecified;
if (params.isMember(jss::ripplerpc))
{
// A `ripplerpc` the server cannot honor is a bad parameter, so the second check reports
// that code. The first keeps the method-not-found code shipped versions report.
if (!params[jss::ripplerpc].isString())
{
usage.charge(resource::kFeeMalformedRpc);
if (!batch)
{
httpReply(400, "ripplerpc is not a string", output, rpcJ);
if (!reject(400, rpc::kJsonRpcMethodNotFound, "ripplerpc is not a string"))
return;
}
json::Value r = jsonRPC;
r[jss::error] = makeJsonError(kMethodNotFound, "ripplerpc is not a string");
reply.append(r);
continue;
}
ripplerpc = params[jss::ripplerpc].asString();
auto const parsed = rpcVersion(params[jss::ripplerpc].asString());
if (!parsed)
{
usage.charge(resource::kFeeMalformedRpc);
if (!reject(
400, rpc::kJsonRpcInvalidParams, "ripplerpc is not a supported version"))
return;
continue;
}
envelope = *parsed;
}
/**
@@ -847,11 +989,11 @@ ServerHandler::processRequest(
user.remove_suffix(user.size());
}
JLOG(journal_.debug()) << "Query: " << strMethod << params;
JLOG(journal_.debug()) << "Query: " << strMethod << rpc::loggable(params);
// Provide the JSON-RPC method as the field "command" in the request.
params[jss::command] = strMethod;
JLOG(journal_.trace()) << "doRpcCommand:" << strMethod << ":" << params;
JLOG(journal_.trace()) << "doRpcCommand:" << strMethod << ":" << rpc::loggable(params);
resource::Charge loadType = resource::kFeeReferenceRpc;
@@ -878,12 +1020,9 @@ ServerHandler::processRequest(
}
catch (std::exception const& ex)
{
// LCOV_EXCL_START
result = rpc::makeError(RpcInternal);
JLOG(journal_.error())
<< "Internal error : " << ex.what()
<< " when processing request: " << json::Compact{json::Value{params}};
// LCOV_EXCL_STOP
JLOG(journal_.error()) << "Internal error : " << ex.what()
<< " when processing request: " << rpc::loggable(params);
}
auto end = std::chrono::system_clock::now();
@@ -894,72 +1033,9 @@ ServerHandler::processRequest(
if (usage.warn())
result[jss::warning] = jss::load;
json::Value r(json::ValueType::Object);
if (ripplerpc >= "2.0")
{
if (result.isMember(jss::error))
{
result[jss::status] = jss::error;
result["code"] = result[jss::error_code];
result["message"] = result[jss::error_message];
result.removeMember(jss::error_message);
JLOG(journal_.debug())
<< "rpcError: " << result[jss::error] << ": " << result[jss::error_message];
r[jss::error] = std::move(result);
}
else
{
result[jss::status] = jss::success;
r[jss::result] = std::move(result);
}
}
else
{
// Always report "status". On an error report the request as
// received.
if (result.isMember(jss::error))
{
auto rq = params;
if (rq.isObject())
{ // But mask potentially sensitive information.
if (rq.isMember(jss::passphrase.cStr()))
rq[jss::passphrase.cStr()] = "<masked>";
if (rq.isMember(jss::secret.cStr()))
rq[jss::secret.cStr()] = "<masked>";
if (rq.isMember(jss::seed.cStr()))
rq[jss::seed.cStr()] = "<masked>";
if (rq.isMember(jss::seed_hex.cStr()))
rq[jss::seed_hex.cStr()] = "<masked>";
}
result[jss::status] = jss::error;
result[jss::request] = rq;
JLOG(journal_.debug())
<< "rpcError: " << result[jss::error] << ": " << result[jss::error_message];
}
else
{
result[jss::status] = jss::success;
}
r[jss::result] = std::move(result);
}
if (params.isMember(jss::jsonrpc))
r[jss::jsonrpc] = params[jss::jsonrpc];
if (params.isMember(jss::ripplerpc))
r[jss::ripplerpc] = params[jss::ripplerpc];
if (params.isMember(jss::id))
r[jss::id] = params[jss::id];
if (batch)
{
reply.append(std::move(r));
}
else
{
reply = std::move(r);
}
int const status = shapeReply(envelope, std::move(result), params, batch, reply, journal_);
if (!batch)
httpStatus = status;
if (reply.isMember(jss::result) && reply[jss::result].isMember(jss::result))
{
@@ -972,25 +1048,6 @@ ServerHandler::processRequest(
}
}
// If we're returning an error_code, use that to determine the HTTP status.
int const httpStatus = [&reply] {
// This feature is enabled with ripplerpc version 3.0 and above.
// Before ripplerpc version 3.0 always return 200.
if (reply.isMember(jss::ripplerpc) && reply[jss::ripplerpc].isString() &&
reply[jss::ripplerpc].asString() >= "3.0")
{
// If there's an error_code, use that to determine the HTTP Status.
if (reply.isMember(jss::error) && reply[jss::error].isMember(jss::error_code) &&
reply[jss::error][jss::error_code].isInt())
{
int const errCode = reply[jss::error][jss::error_code].asInt();
return rpc::errorCodeHttpStatus(static_cast<ErrorCodeI>(errCode));
}
}
// Return OK.
return 200;
}();
auto response = to_string(reply);
rpcTime_.notify(
@@ -999,21 +1056,22 @@ ServerHandler::processRequest(
++rpcRequests_;
rpcSize_.notify(beast::insight::Event::value_type{response.size()});
response += '\n';
// The serialized reply is in hand, so it is logged as built; the masked copy and its second
// serialization are paid for only when a credential has to be replaced.
if (auto stream = journal_.debug())
{
static int const kMaxSize = 10000;
if (response.size() <= kMaxSize)
if (rpc::hasSecret(reply))
{
stream << "Reply: " << response;
stream << "Reply: " << rpc::loggable(reply);
}
else
{
stream << "Reply: " << response.substr(0, kMaxSize);
stream << "Reply: " << std::string_view{response}.substr(0, rpc::kMaxLoggedChars);
}
}
response += '\n';
httpReply(httpStatus, response, output, rpcJ);
}

View File

@@ -8,6 +8,7 @@
#include <xrpld/rpc/Role.h>
#include <xrpld/rpc/detail/AssetCache.h>
#include <xrpld/rpc/detail/LegacyPathFind.h>
#include <xrpld/rpc/detail/MaskSecrets.h>
#include <xrpld/rpc/detail/Pathfinder.h>
#include <xrpld/rpc/detail/RPCHelpers.h>
#include <xrpld/rpc/detail/Tuning.h>
@@ -1018,7 +1019,8 @@ transactionSign(
// could change the signing prefix of an alternate signature field.
std::shared_ptr<ReadView const> const ledger = app.getOpenLedger().current();
auto j = app.getJournal("RPCHandler");
JLOG(j.debug()) << "transactionSign: " << jvRequest;
// The next statement reads the signing secret out of this same request.
JLOG(j.debug()) << "transactionSign: " << loggable(jvRequest);
// Add and amend fields based on the transaction type.
SigningForParams signForParams;
@@ -1055,7 +1057,7 @@ transactionSubmit(
auto const& ledger = app.getOpenLedger().current();
auto j = app.getJournal("RPCHandler");
JLOG(j.debug()) << "transactionSubmit: " << jvRequest;
JLOG(j.debug()) << "transactionSubmit: " << loggable(jvRequest);
// Add and amend fields based on the transaction type.
SigningForParams signForParams;
@@ -1177,7 +1179,7 @@ transactionSignFor(
{
auto const& ledger = app.getOpenLedger().current();
auto j = app.getJournal("RPCHandler");
JLOG(j.debug()) << "transactionSignFor: " << jvRequest;
JLOG(j.debug()) << "transactionSignFor: " << loggable(jvRequest);
// Verify presence of the signer's account field.
char const accountField[] = "account";
@@ -1301,7 +1303,7 @@ transactionSubmitMultiSigned(
{
auto const& ledger = app.getOpenLedger().current();
auto j = app.getJournal("RPCHandler");
JLOG(j.debug()) << "transactionSubmitMultiSigned: " << jvRequest;
JLOG(j.debug()) << "transactionSubmitMultiSigned: " << loggable(jvRequest);
// When multi-signing, the "Sequence" and "SigningPubKey" fields must
// be passed in by the caller.

View File

@@ -4,6 +4,7 @@
#include <xrpld/rpc/Context.h>
#include <xrpl/json/json_value.h>
#include <xrpl/protocol/ErrorCodes.h>
#include <xrpl/protocol/jss.h>
#include <xrpl/server/NetworkOPs.h>
@@ -11,6 +12,13 @@
namespace xrpl {
/**
* Closes the open ledger on a stand-alone server.
*
* @param context The request. Its `params` are not read.
* @return `ledger_current_index` of the ledger the close opens, or
* `notStandAlone` when the server is on a network.
*/
json::Value
doLedgerAccept(rpc::JsonContext& context)
{
@@ -18,7 +26,7 @@ doLedgerAccept(rpc::JsonContext& context)
if (!context.app.config().standalone())
{
jvResult[jss::error] = "notStandAlone";
rpc::injectError(RpcNotStandAlone, jvResult);
}
else
{

View File

@@ -1038,7 +1038,7 @@ doLedgerEntry(rpc::JsonContext& context)
{
if (context.apiVersion < 2u)
{
jvResult[jss::error] = "unknownOption";
rpc::injectError(RpcUnknownOption, jvResult);
return jvResult;
}
return rpc::makeParamError("No ledger_entry params provided.");

View File

@@ -24,6 +24,9 @@
namespace xrpl::ledger_entry_helpers {
// These helpers name the malformed field in the `error` token and report `invalidParams` as the
// code, whatever the token is. A client has read 31 for every one of these tokens for years, so the
// code is deliberately not derived from the token here.
inline std::unexpected<json::Value>
missingFieldError(json::StaticString const field, std::optional<std::string> err = std::nullopt)
{

View File

@@ -42,6 +42,17 @@
namespace xrpl {
/**
* Picks the `Sequence` a simulated transaction runs with.
*
* @param txJson The transaction, which carries an `Account` member.
* @param context The request, read for the open ledger and the queue.
* @return 0 when the transaction names a `TicketSequence`, otherwise the
* account's next queueable sequence. On either path, the error to
* report when `Account` is not a string or does not parse as an
* account; without a `TicketSequence`, also when the account is not
* in the open ledger.
*/
static std::expected<std::uint32_t, json::Value>
getAutofillSequence(json::Value const& txJson, rpc::JsonContext& context)
{
@@ -50,10 +61,10 @@ getAutofillSequence(json::Value const& txJson, rpc::JsonContext& context)
auto const& accountStr = txJson[jss::Account];
if (!accountStr.isString())
{
// sanity check, should fail earlier
// LCOV_EXCL_START
// The earlier check requires `Account` to be present, not to be a string, so this is the
// type check. Without it `asString` below throws on a numeric value, which degrades a clean
// field error into an internal one.
return std::unexpected(rpc::invalidFieldError("tx.Account"));
// LCOV_EXCL_STOP
}
auto const srcAddressID = parseBase58<AccountID>(accountStr.asString());
if (!srcAddressID.has_value())
@@ -240,6 +251,19 @@ getTxJsonFromParams(json::Value const& params)
return txJson;
}
/**
* Applies @p transaction to a copy of the open ledger as a dry run.
*
* @param context The request, read for `binary`.
* @param transaction The transaction to apply.
* @return The engine result with `applied` and `ledger_index`, and the
* transaction as `tx_blob` when `binary` is true, otherwise as
* `tx_json`. Its metadata follows as `meta_blob` or `meta` only
* when the engine produced any, which it does when the result is
* `tesSUCCESS` or a `tec` code, since both apply the transaction
* to the view. A `tel`, `tem`, `tef` or `ter` result applies
* nothing and carries no metadata.
*/
static json::Value
simulateTxn(rpc::JsonContext& context, std::shared_ptr<Transaction> transaction)
{
@@ -266,12 +290,11 @@ simulateTxn(rpc::JsonContext& context, std::shared_ptr<Transaction> transaction)
}
else
{
// shouldn't be hit
// LCOV_EXCL_START
// Every TER this can hold names a token, so this arm states the fallback rather than a
// result any transaction reaches.
jvResult[jss::engine_result] = "unknown";
jvResult[jss::engine_result_code] = result.ter;
jvResult[jss::engine_result_message] = "unknown";
// LCOV_EXCL_STOP
}
if (token == "tesSUCCESS")
@@ -307,10 +330,20 @@ simulateTxn(rpc::JsonContext& context, std::shared_ptr<Transaction> transaction)
return jvResult;
}
// {
// tx_blob: <string> XOR tx_json: <object>,
// binary: <bool>
// }
/**
* Dry-runs a transaction against the open ledger without submitting it.
*
* `params` carry `tx_blob` or `tx_json`, one of the two, and optionally
* `binary`. A credential in `params` is refused. A `tx_json` missing
* `Sequence`, `Fee` or `SigningPubKey` has it filled in, and one missing
* `NetworkID` has it filled in where the network's ID is above 1024.
*
* @param context The request.
* @return The result `simulateTxn` builds, or an error object:
* `invalidTransaction` with `error_exception` when the transaction
* does not build, `internalSimulate` with `error_exception` when
* applying it throws.
*/
json::Value
doSimulate(rpc::JsonContext& context)
{
@@ -353,7 +386,7 @@ doSimulate(rpc::JsonContext& context)
catch (std::exception& e)
{
json::Value jvResult = json::ValueType::Object;
jvResult[jss::error] = "invalidTransaction";
rpc::injectError(RpcInvalidTransaction, jvResult);
jvResult[jss::error_exception] = e.what();
return jvResult;
}
@@ -377,15 +410,13 @@ doSimulate(rpc::JsonContext& context)
{
return simulateTxn(context, transaction);
}
// LCOV_EXCL_START this is just in case, so xrpld doesn't crash
catch (std::exception const& e)
{
json::Value jvResult = json::ValueType::Object;
jvResult[jss::error] = "internalSimulate";
rpc::injectError(RpcInternalSimulate, jvResult);
jvResult[jss::error_exception] = e.what();
return jvResult;
}
// LCOV_EXCL_STOP
}
} // namespace xrpl

View File

@@ -37,10 +37,21 @@ getFailHard(rpc::JsonContext const& context)
context.params.isMember(jss::fail_hard) && context.params[jss::fail_hard].asBool());
}
// {
// tx_blob: <string> XOR tx_json: <object>,
// secret: <secret>
// }
/**
* Submits a transaction to the network.
*
* `params` carry `tx_blob`, a signed transaction, or `tx_json` with a
* signing credential, which the server signs first when it allows signing;
* that path is deprecated. `fail_hard` keeps a transaction the local checks
* fail from being relayed.
*
* @param context The request.
* @return The engine result and the transaction, or an error object:
* `invalidTransaction` with `error_exception` when the blob does not
* decode or fails the local checks, `internalSubmit` with
* `error_exception` when processing throws, `internalJson` when
* building the reply throws.
*/
json::Value
doSubmit(rpc::JsonContext& context)
{
@@ -90,7 +101,7 @@ doSubmit(rpc::JsonContext& context)
}
catch (std::exception& e)
{
jvResult[jss::error] = "invalidTransaction";
rpc::injectError(RpcInvalidTransaction, jvResult);
jvResult[jss::error_exception] = e.what();
return jvResult;
@@ -106,7 +117,7 @@ doSubmit(rpc::JsonContext& context)
context.app.getHashRouter(), *stTx, context.ledgerMaster.getCurrentLedger()->rules());
if (validity != Validity::Valid)
{
jvResult[jss::error] = "invalidTransaction";
rpc::injectError(RpcInvalidTransaction, jvResult);
jvResult[jss::error_exception] = "fails local checks: " + reason;
return jvResult;
@@ -117,7 +128,7 @@ doSubmit(rpc::JsonContext& context)
auto transaction = std::make_shared<Transaction>(stTx, reason, context.app);
if (transaction->getStatus() != TransStatus::NEW)
{
jvResult[jss::error] = "invalidTransaction";
rpc::injectError(RpcInvalidTransaction, jvResult);
jvResult[jss::error_exception] = "fails local checks: " + reason;
return jvResult;
@@ -133,7 +144,7 @@ doSubmit(rpc::JsonContext& context)
}
catch (std::exception& e)
{
jvResult[jss::error] = "internalSubmit";
rpc::injectError(RpcInternalSubmit, jvResult);
jvResult[jss::error_exception] = e.what();
return jvResult;
@@ -179,7 +190,7 @@ doSubmit(rpc::JsonContext& context)
}
catch (std::exception& e)
{
jvResult[jss::error] = "internalJson";
rpc::injectError(RpcInternalJson, jvResult);
jvResult[jss::error_exception] = e.what();
return jvResult;

View File

@@ -9,6 +9,7 @@
#include <xrpl/basics/chrono.h>
#include <xrpl/json/json_value.h>
#include <xrpl/ledger/ReadView.h>
#include <xrpl/protocol/ErrorCodes.h>
#include <xrpl/protocol/jss.h>
#include <rpcspec/Errors.hpp>
@@ -37,22 +38,23 @@ TransactionEntryHandler::process(Input const& input) const
if (!input.txHash &&
input.txHash.error() == ::rpc::spec::handlers::transaction_entry::TxHashError::Missing)
{
output.error = "fieldNotFoundTransaction";
output.error = ::rpc::Status{
RpcFieldNotFoundTransaction, missingFieldMessage(std::string{jss::tx_hash.cStr()})};
}
else if (output.ledger->open())
{
// We don't work on ledger current.
output.error = "notYetImplemented";
output.error = ::rpc::Status{RpcNotYetImplemented};
}
else if (!input.txHash)
{
output.error = "malformedRequest";
output.error = ::rpc::Status{RpcMalformedRequest};
}
else
{
std::tie(output.tx, output.meta) = output.ledger->txRead(*input.txHash);
if (!output.tx)
output.error = "transactionNotFound";
output.error = ::rpc::Status{RpcTransactionNotFound};
}
return output;
@@ -68,7 +70,9 @@ TransactionEntryHandler::writeResult(json::Value& value, Output const& output) c
if (output.error)
{
value[jss::error] = std::string{*output.error};
// The error travels in the Output, not as a failed process(), so the reply keeps the
// ledger fields written above beside the token, code and message.
injectSpecError(value, *output.error);
return;
}

View File

@@ -15,7 +15,6 @@
#include <functional>
#include <memory>
#include <optional>
#include <string_view>
namespace xrpl::rpc {
@@ -25,16 +24,38 @@ public:
struct Output
{
std::shared_ptr<ReadView const> ledger;
std::optional<std::string_view> error;
/**
* The error reported beside the ledger fields when the lookup fails.
*/
std::optional<::rpc::Status> error;
std::shared_ptr<STTx const> tx;
std::shared_ptr<STObject const> meta;
};
explicit TransactionEntryHandler(JsonContext&);
/**
* Looks the transaction up in the selected ledger.
*
* @param input The parsed request: the ledger selected, and the `tx_hash`
* read or the reason there is none.
* @return The ledger with the transaction and its metadata, or the ledger
* with an error carrying its code: `fieldNotFoundTransaction`
* without a `tx_hash`, `notYetImplemented` when the ledger is the
* open one, `malformedRequest` when `tx_hash` is not a hex string,
* `transactionNotFound` when the ledger does not hold it. A ledger
* that cannot be selected is returned as the unexpected Status.
*/
[[nodiscard]] std::expected<Output, ::rpc::Status>
process(Input const& input) const;
/**
* Writes the reply: the ledger fields, then either the error with its
* code and message, or the transaction and its metadata.
*
* @param value The reply object written into.
* @param output The result of `process`.
*/
void
writeResult(json::Value& value, Output const& output) const;