SocketCluster / SocketCluster/socketcluster
Add safe mode so that SC rejects any invalid non-JSON packet
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 6.2k
- Forks
- 318
- PR merge metrics
- No merged PRs in 30d
Description
Right now SC supports non-JSON strings sent using socket.send('This is a message').
It would be nice to add a config option so that it can be disabled and only allow valid SC JSON strings. This could make certain kinds of DoS attacks more expensive and complicated.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing how socket.send('This is a message') is handled and where SocketCluster configuration options are defined. Determine the validation boundary and configuration behavior; done means a safe-mode setting rejects invalid non-JSON packets while valid SC JSON strings remain accepted.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, nodejs
- Domain
- backend, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100