mirror of
https://github.com/nlohmann/json.git
synced 2026-10-05 06:00:29 +00:00
deploy: ad2c14b985
This commit is contained in:
File diff suppressed because one or more lines are too long
@@ -23,7 +23,7 @@ The primary threat is therefore **untrusted input**: JSON text or binary data (B
|
||||
- **Strict parsing.** The parser accepts exactly the JSON grammar of [RFC 8259](https://datatracker.ietf.org/doc/html/rfc8259). Extensions such as [comments](https://json.nlohmann.me/features/comments/index.md) and [trailing commas](https://json.nlohmann.me/features/trailing_commas/index.md) must be enabled explicitly. Invalid UTF-8 is rejected.
|
||||
- **Errors are reported, not ignored.** Malformed input results in a [`parse_error`](https://json.nlohmann.me/home/exceptions/#parse-errors) with the byte position of the error. Binary readers do not trust announced sizes: strings and binary values grow only as bytes are actually read, arrays reserve at most a fixed number of elements up front, and sizes that no container can hold are rejected.
|
||||
- **Memory is owned by values.** Each `basic_json` value owns its content, and there is no manual memory management in user code. The destructor does not recurse, so destroying a deeply nested value does not exhaust the stack.
|
||||
- **Bounded recursion.** The JSON parser and the binary readers keep their state in explicit stacks instead of recursing per nesting level. Operations that walk a value, such as [`dump`](https://json.nlohmann.me/api/basic_json/dump/index.md), copying, hashing, and [`merge_patch`](https://json.nlohmann.me/api/basic_json/merge_patch/index.md), recurse only up to a fixed depth and continue with an explicit stack below it. Some operations, such as comparison, [`diff`](https://json.nlohmann.me/api/basic_json/diff/index.md), [`flatten`](https://json.nlohmann.me/api/basic_json/flatten/index.md), and the binary writers, still recurse once per nesting level; work on them is in progress. Applications that process untrusted input can limit its nesting depth with a [parser callback](https://json.nlohmann.me/features/parsing/parser_callbacks/index.md).
|
||||
- **Bounded recursion.** The JSON parser and the binary readers keep their state in explicit stacks instead of recursing per nesting level. Operations that walk a value, such as [`dump`](https://json.nlohmann.me/api/basic_json/dump/index.md), copying, comparison, hashing, and [`merge_patch`](https://json.nlohmann.me/api/basic_json/merge_patch/index.md), recurse only up to a fixed depth and continue with an explicit stack below it. Some operations, such as [`diff`](https://json.nlohmann.me/api/basic_json/diff/index.md), [`flatten`](https://json.nlohmann.me/api/basic_json/flatten/index.md), and the binary writers, still recurse once per nesting level; work on them is in progress. Applications that process untrusted input can limit its nesting depth with a [parser callback](https://json.nlohmann.me/features/parsing/parser_callbacks/index.md).
|
||||
- **Invariants are checked.** The class invariant (for instance, that the pointer for the stored type is never null) is checked with runtime assertions throughout the test suite.
|
||||
|
||||
## Common weaknesses
|
||||
|
||||
Reference in New Issue
Block a user