Skip to content

Version 0.4.0 - DoS Protection

Choose a tag to compare

@kylehowells kylehowells released this 24 Mar 22:13
· 32 commits to master since this release

New Features

ParserLimits - Configurable DoS Protection

swift-justhtml now includes configurable limits to protect against denial-of-service attacks from malicious HTML input:

// Default limits are applied automatically (recommended)
let doc = try JustHTML(untrustedHTML)

// Custom limits for servers with more resources
var limits = ParserLimits()
limits.maxNestingDepth = 2048
let doc = try JustHTML(html, limits: limits)

// Stricter limits for resource-constrained devices
let doc = try JustHTML(html, limits: .strict)

// Disable limits for trusted content only
let doc = try JustHTML(trustedHTML, limits: .unlimited)

Limits

Limit Default Description
maxEntityNameLength 255 Prevents memory attacks from extremely long invalid entity names (e.g., &aaaa... with millions of characters)
maxNestingDepth 512 Prevents stack overflow from extremely deep DOM nesting (e.g., 10,000+ nested <div> elements)

Presets

Preset Entity Length Nesting Depth Use Case
.default 255 512 General use
.strict 128 256 Mobile/embedded
.unlimited unlimited unlimited Trusted content only

Test Results

All html5lib tests continue to pass:

Test Suite Passed Failed
Tree Construction 1,831 0
Tokenizer 6,810 0
Total 8,641 0

Documentation