Skip to content

fix(internal/common): limit lexer recursion depth - #776

Merged
pavelnikolov merged 2 commits into
mainfrom
fix/add-parser-max-depth
Sep 22, 2026
Merged

pavelnikolov merged 2 commits into
mainfrom
fix/add-parser-max-depth

Conversation

@pavelnikolov

@pavelnikolov pavelnikolov commented Sep 22, 2026 •

Copy link
Copy Markdown
Member
  • Limit the maximum parsing recursion depth in the lexer
  • Improve docs to recommend limiting the length of queries by untrusted clients
  • Add query max length check during query validation as well to match Exec and Subscribe

Copilot AI lite review requested due to automatic review settings September 22, 2026 11:16

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Clarify in README.md and SECURITY.md that MaxQueryLength applies only to Schema.Exec.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 Low severity

Open (2)
What changed in this PR

This PR limits parser recursion depth to reduce stack-overflow risk and documents query-size protections.

Changes:

  • Adds depth tracking for selections, literals, and list types.
  • Adds boundary tests for parser nesting depth.
  • Documents MaxQueryLength and query-length security guidance.
  • Clarifies that MaxQueryLength is enforced only by Schema.Exec, not Validate or Subscribe.
File Summary
SECURITY.md Adds query-length security guidance; scope MaxQueryLength to Schema.Exec.
README.md Documents MaxQueryLength; clarify its enforcement scope.
internal/​query/​query.go Guards nested selection parsing.
internal/​query/​query_test.go Adds parser-depth boundary tests.
internal/​common/​types.go Guards nested list types.
internal/​common/​literals.go Guards nested literals.
internal/​common/​lexer.go Implements recursion-depth tracking and enforcement.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread README.md
Comment thread SECURITY.md
@pavelnikolov
pavelnikolov force-pushed the fix/add-parser-max-depth branch from ab330df to dfa14e4 Compare September 22, 2026 11:22
@pavelnikolov
pavelnikolov merged commit 55de4c0 into main Sep 22, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants