mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-06 02:48:13 +00:00
perf(mcp): O(1) character precheck before the exact byte size guard in open_envelope
This commit is contained in:
parent
2883e36a97
commit
9176744735
2 changed files with 23 additions and 0 deletions
|
|
@ -257,6 +257,11 @@ def open_envelope(
|
|||
"""
|
||||
if not is_envelope(candidate):
|
||||
return NotAnEnvelope()
|
||||
# UTF-8 byte length is never below character length, so a character count already over the
|
||||
# cap rejects an oversize candidate in O(1) without encoding it; the exact byte check then
|
||||
# runs only on candidates already bounded to <= MAX_ENVELOPE_BYTES characters.
|
||||
if len(candidate) > MAX_ENVELOPE_BYTES:
|
||||
return MalformedPayload()
|
||||
if len(candidate.encode("utf-8", "surrogatepass")) > MAX_ENVELOPE_BYTES:
|
||||
return MalformedPayload()
|
||||
claims = _decode_claims(candidate.removeprefix(ENVELOPE_PREFIX), keys.signing_key)
|
||||
|
|
|
|||
|
|
@ -387,6 +387,24 @@ def test_open_size_guard_measures_bytes_not_characters():
|
|||
decode.assert_not_called()
|
||||
|
||||
|
||||
def test_open_size_guard_rejects_oversize_character_count_before_decode():
|
||||
"""A candidate whose character count already exceeds the cap is rejected up front, before the
|
||||
decode path, so an arbitrarily long hostile string is not run through HMAC/decrypt. The cheap
|
||||
character precheck makes this O(1) since UTF-8 byte length is never below character length."""
|
||||
from unittest.mock import patch
|
||||
|
||||
from litellm.proxy._experimental.mcp_server.outbound_credentials import envelope
|
||||
|
||||
candidate = ENVELOPE_PREFIX + ("a" * (MAX_ENVELOPE_BYTES + 1))
|
||||
assert len(candidate) > MAX_ENVELOPE_BYTES
|
||||
|
||||
with patch.object(envelope, "_decode_claims", side_effect=AssertionError("decode reached")) as decode:
|
||||
result = open_envelope(candidate, _KEYS, _NOW)
|
||||
|
||||
assert isinstance(result, MalformedPayload)
|
||||
decode.assert_not_called()
|
||||
|
||||
|
||||
def test_is_envelope_detects_only_prefixed_values():
|
||||
assert is_envelope(_sealed_token(_full_grant()))
|
||||
raw_jwt = jwt.encode({"sub": "user-123"}, _SIGNING_KEY, algorithm="HS256")
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue