Class SecuritySettings
- Namespace
- Nerdbank.Json
- Assembly
- Nerdbank.Json.dll
Security settings that may be applied to serialization.
public record SecuritySettings : IEquatable<SecuritySettings>
- Inheritance
-
SecuritySettings
- Implements
- Inherited Members
Remarks
Applications may derive from this class to add additional settings that its custom converters may honor. Added settings should have secure defaults.
Constructors
SecuritySettings()
Initializes a new instance of the SecuritySettings class with secure defaults (those matching the values found in UntrustedData).
public SecuritySettings()
Fields
TrustedData
Default settings to use with trusted data.
public static readonly SecuritySettings TrustedData
Field Value
Remarks
This value is optimized for high performance assuming the data is trustworthy, and should not be used with untrusted data.
UntrustedData
Default settings to use when (de)serializing untrusted data.
public static readonly SecuritySettings UntrustedData
Field Value
Remarks
This value is optimized for security when processing untrusted data.
Properties
MaxObjectMemberCount
Gets the maximum number of members permitted in a single untyped JSON object (or dynamic object such as ExpandoObject) when deserializing.
public int MaxObjectMemberCount { get; init; }
Property Value
- int
The default value is 1,000,000.
Remarks
This bounds memory and, for structures whose insertion cost grows with size, CPU when processing untrusted data. It applies only to the optional untyped and dynamic converters; strongly typed objects have a fixed member set.