dotnet / dotnet/AspNetCore.Docs

clarify implications of disabling SignalR MaximumReceiveMessageSize

Open
#32,467 1 comment 0 reactions 1 assignee Claimed by @wadepickett View on GitHub
aspnet-core/svc aspnetcore-signalr/subsvc SignalR Source - Docs.ms
Dominant language
C#
Stars
13.1k
Forks
24.6k
Avg merge
1d 3h
Merged PRs (30d)
97

Description

### Description

This page says that

> Increasing the value might increase the risk of Denial of service (DoS) attacks.

Under what conditions does or doesn't it increase the risk of Denial of Service (DoS) attacks? Is this risk mitigated at all by using an AuthenticationScheme on the SignalR hub requiring bearer access tokens in the HTTP headers (i.e. does this prevent unauthorized users from performing DoS attacks)? Are there other implications (security, performance, etc) of increasing the value or disabling the limit entirely?

See also my SO question about this [here](https://stackoverflow.com/questions/78349556/implications-of-disabling-signalr-maximumreceivemessagesize-and-possible-mitigat).

### Page URL

https://learn.microsoft.com/en-us/aspnet/core/signalr/configuration?view=aspnetcore-8.0&tabs=dotnet#configure-server-options

### Content source URL

https://github.com/dotnet/AspNetCore.Docs/blob/main/aspnetcore/signalr/configuration.md

### Document ID

66d252c3-6300-7e28-9aa0-ef2ff66e7a76

### Article author

@bradygaster

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.