Skip to content

Commit 556ea55

Browse files
author
Kiwi
authored
fix: validate encryption context entry lengths (#805)
* fix: validate encryption context entry lengths * fix: reduce encryption context serialization complexity
1 parent 2c0200b commit 556ea55

2 files changed

Lines changed: 25 additions & 0 deletions

File tree

‎src/aws_encryption_sdk/internal/formatting/encryption_context.py‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,14 @@
1616
_LOGGER = logging.getLogger(__name__)
1717

1818

19+
def _validate_encryption_context_entry(key, value):
20+
max_entry_length = aws_encryption_sdk.internal.defaults.MAX_BYTE_ARRAY_SIZE
21+
if len(key) > max_entry_length:
22+
raise SerializationError("The encryption context contains a key that is too large.")
23+
if len(value) > max_entry_length:
24+
raise SerializationError("The encryption context contains a value that is too large.")
25+
26+
1927
def assemble_content_aad(message_id, aad_content_string, seq_num, length):
2028
"""Assembles the Body AAD string for a message body structure.
2129
@@ -72,6 +80,7 @@ def serialize_encryption_context(encryption_context):
7280
)
7381

7482
for key, value in sorted(encryption_context_list, key=lambda x: x[0]):
83+
_validate_encryption_context_entry(key, value)
7584
serialized_context.extend(
7685
struct.pack(
7786
">H{key_size}sH{value_size}s".format(key_size=len(key), value_size=len(value)),

‎test/unit/test_encryption_context.py‎

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -64,6 +64,22 @@ def test_serialize_encryption_context_too_large(self):
6464
)
6565
excinfo.match("The serialized context is too large")
6666

67+
def test_serialize_encryption_context_key_too_large(self):
68+
oversized_key = "a" * (aws_encryption_sdk.internal.defaults.MAX_BYTE_ARRAY_SIZE + 1)
69+
with pytest.raises(SerializationError) as excinfo:
70+
aws_encryption_sdk.internal.formatting.encryption_context.serialize_encryption_context(
71+
{oversized_key: "value"}
72+
)
73+
excinfo.match("The encryption context contains a key that is too large.")
74+
75+
def test_serialize_encryption_context_value_too_large(self):
76+
oversized_value = "a" * (aws_encryption_sdk.internal.defaults.MAX_BYTE_ARRAY_SIZE + 1)
77+
with pytest.raises(SerializationError) as excinfo:
78+
aws_encryption_sdk.internal.formatting.encryption_context.serialize_encryption_context(
79+
{"key": oversized_value}
80+
)
81+
excinfo.match("The encryption context contains a value that is too large.")
82+
6783
def test_serialize_encryption_context_unencodable(self):
6884
"""Validate that the serialize_encryption_context
6985
function behaves as expected when presented

0 commit comments

Comments
 (0)