mirror of
https://github.com/nlohmann/json.git
synced 2026-10-03 21:20:30 +00:00
deploy: 63c10a51fc
This commit is contained in:
@@ -30,6 +30,17 @@ that an attacker controls, passed to [`parse`](../api/basic_json/parse.md), [`ac
|
||||
not a security boundary. Such preconditions are checked with [runtime assertions](../features/assertions.md) in debug
|
||||
builds; functions such as [`at`](../api/basic_json/at.md) offer checked access with exceptions.
|
||||
|
||||
```mermaid
|
||||
flowchart LR
|
||||
A[Untrusted input] --> B[Parser]
|
||||
A --> C[SAX interface]
|
||||
A --> D[Binary readers]
|
||||
B --> E["Value tree (basic_json)"]
|
||||
C --> E
|
||||
D --> E
|
||||
E --> F[Trusted caller]
|
||||
```
|
||||
|
||||
## Secure design
|
||||
|
||||
- **Strict parsing.** The parser accepts exactly the JSON grammar of [RFC 8259](https://datatracker.ietf.org/doc/html/rfc8259).
|
||||
|
||||
File diff suppressed because one or more lines are too long
@@ -18,6 +18,17 @@ The primary threat is therefore **untrusted input**: JSON text or binary data (B
|
||||
- **Untrusted:** all serialized input read by the parser, the SAX interface, and the binary readers. The library must handle every possible input by either producing a value or throwing a [`parse_error`](https://json.nlohmann.me/home/exceptions/#parse-errors) (or returning `false` when exceptions are disabled for the call).
|
||||
- **Trusted:** the C++ code that calls the library. Calling a function with violated preconditions, for instance accessing an array with [`operator[]`](https://json.nlohmann.me/api/basic_json/operator%5B%5D/index.md) out of range, is a programming error and not a security boundary. Such preconditions are checked with [runtime assertions](https://json.nlohmann.me/features/assertions/index.md) in debug builds; functions such as [`at`](https://json.nlohmann.me/api/basic_json/at/index.md) offer checked access with exceptions.
|
||||
|
||||
```
|
||||
flowchart LR
|
||||
A[Untrusted input] --> B[Parser]
|
||||
A --> C[SAX interface]
|
||||
A --> D[Binary readers]
|
||||
B --> E["Value tree (basic_json)"]
|
||||
C --> E
|
||||
D --> E
|
||||
E --> F[Trusted caller]
|
||||
```
|
||||
|
||||
## Secure design
|
||||
|
||||
- **Strict parsing.** The parser accepts exactly the JSON grammar of [RFC 8259](https://datatracker.ietf.org/doc/html/rfc8259). Extensions such as [comments](https://json.nlohmann.me/features/comments/index.md) and [trailing commas](https://json.nlohmann.me/features/trailing_commas/index.md) must be enabled explicitly. Invalid UTF-8 is rejected.
|
||||
|
||||
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -103,6 +103,15 @@ make serve -C docs/mkdocs
|
||||
|
||||
The documentation will then be available at <http://127.0.0.1:8000/>. See the documentation of [mkdocs](https://www.mkdocs.org) and [Material for MkDocs](https://squidfunk.github.io/mkdocs-material/) for more information.
|
||||
|
||||
Before opening a pull request, check the documentation like the CI does:
|
||||
|
||||
```
|
||||
make build -C docs/mkdocs # strict build: fails on broken links, anchors, and structure problems
|
||||
make check_mermaid -C docs/mkdocs # checks the Mermaid diagrams (requires Node.js)
|
||||
```
|
||||
|
||||
A new API page also needs an entry in [`docs/docset/docSet.sql`](https://github.com/nlohmann/json/blob/develop/docs/docset/docSet.sql), the search index of the docset; `make build` reports missing entries.
|
||||
|
||||
### Amalgamate the source code
|
||||
|
||||
The single-header files [`single_include/nlohmann/json.hpp`](https://github.com/nlohmann/json/blob/develop/single_include/nlohmann/json.hpp) and [`single_include/nlohmann/json_fwd.hpp`](https://github.com/nlohmann/json/blob/develop/single_include/nlohmann/json_fwd.hpp) are **generated** from the source files in the [`include/nlohmann` directory](https://github.com/nlohmann/json/tree/develop/include/nlohmann). **Do not** edit the files directly; instead, modify the include/nlohmann sources and regenerate the files by executing:
|
||||
|
||||
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user