Skip to content

AUS-1007: Give the obsolete members diagnostic ids - #168

Merged
Astn merged 5 commits into
masterfrom
aus-1007-diagnostic-ids
Sep 26, 2026
Merged

Astn merged 5 commits into
masterfrom
aus-1007-diagnostic-ids

Conversation

@Astn

@Astn Astn commented Sep 26, 2026

Copy link
Copy Markdown
Owner

AUS-1001 item 5 of the 2.0.0 sequence, decided in T7 Q3.

  • Config.SetBeforeProcessHandler, Handler.RegisterFuction and Handler.UnRegisterFunction carry DiagnosticId (JSONRPC0001 to JSONRPC0003) and UrlFormat on net8.0 and net10.0; the netstandard assets keep the id in the message text. The constants live in one file, Json-Rpc/Obsoletions.cs, with the JSONRPC0xxx and JSONRPC1xxx ranges reserved.
  • docs/obsoletions.md is the page the diagnostic link resolves to; it is added to the site, and the site build keeps a heading that is exactly a diagnostic id in its original case so the #JSONRPC0001 fragments resolve. No existing anchor changes.
  • The test project's #pragma warning disable CS0618 pairs also disable the new ids, so the build has no new warnings; ObsoletionTests asserts each attribute's id, URL and message, and that the ids in the core assembly are unique and in the obsoletion range.
  • CHANGELOG 2.0.0 gains a Deprecated subsection naming the removal major (3.0); README "Versioning and support" gains a Deprecations bullet.

Verification: Release build of the full solution with no new warnings, 1220 tests on net8.0 and net10.0, the request-path checker (23 listed uses, none unlisted), the chart check and the site build. The reviewer confirmed with a scratch consumer that the warning shown is JSONRPC0002 with the URL, not CS0618, and read the attributes back from all four built assets.

Stacked on #167; once that merges, this diff is the single commit.

Names beginning with rpc. and the name $/cancelRequest are refused by one check in SMDServiceCollection (Add, the indexer setter and AddBatch before any entry is copied), which every registration path reaches: BindMethod, the attribute binder and RegisterFuction through AddService, BindInterface through AddBatch. BindInterface drops its own rpc. test. An internal AddReserved keeps the duplicate rule for the library's later rpc.discover registration. README, CHANGELOG and docs/upgrading.md carry the change.
The core now bounds what it admits: a document over JsonRpcLimits.MaxDocumentBytes (4 MiB by default) or a batch with more than MaxBatchCount entries (1024) is answered with -32600 and a data object naming the limit and the configured maximum, before anything is parsed or executed. The byte check runs at every public Process and ProcessAsync entry before any copy, flattening or transcoding (string overloads measure the UTF-8 byte count); the batch check runs after a full parse and before the first dispatch, so no prefix of an over-long batch executes. Config.SetLimits sets the process-wide value or a per-session override; zero disables a field and JsonRpcLimits.Unlimited restores the 1.x behaviour. Kestrel's MaxRequestBytes stays and is met first. README, SECURITY.md, CHANGELOG and docs/upgrading.md describe the limits and the staged host-responsibility paragraph.
AUS-1004: Add JsonRpcLimits with document and batch bounds
@Astn
Astn merged commit 97bb1ec into master Sep 26, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant