Skip to main content

MAX_JSON_DEPTH

Constant MAX_JSON_DEPTH 

Source
pub const MAX_JSON_DEPTH: usize = 64;
Expand description

The deepest JSON document this library will digest, sign or verify.

Depth counts from the top of the credential: the document itself is depth 1, and each value inside an object or array is one deeper than its container. A VSC’s object.value therefore sits at depth 4, and a top-level member such as credentialStatus at depth 2.

§Why there is a bound

Digesting, signing and verifying clone, serialize and canonicalize a credential, and each of those recurses once per level of nesting. A value nested a few thousand levels deep exhausts the stack, and a stack overflow aborts the process — it is not an error a caller can handle. The members this library holds as open JSON are where such a value gets in: a VSC’s object.value and unmodelled subject members, credentialStatus, and the unmodelled members in DTGCommon::extra.

§Why this value

serde_json already refuses to parse JSON nested 128 levels deep, so a credential that arrived over the wire is bounded before it gets here. 64 stays well under that — nothing this library signs is too deep for a stock verifier to parse back — and is still far more than any credential in the specification needs.

§What it cannot do

A serde_json::Value is dropped recursively as well. A caller already holding a value deep enough to overflow the stack will overflow it when that value goes out of scope, whatever this library returns. The parser is the real boundary: serde_json applies its limit by default, so leave it on.