Table of Contents

Class SecuritySettings

Namespace
Nerdbank.Json
Assembly
Nerdbank.Json.dll

Security settings that may be applied to serialization.

public record SecuritySettings : IEquatable<SecuritySettings>
Inheritance
SecuritySettings
Implements
Inherited Members

Remarks

Applications may derive from this class to add additional settings that its custom converters may honor. Added settings should have secure defaults.

Constructors

SecuritySettings()

Initializes a new instance of the SecuritySettings class with secure defaults (those matching the values found in UntrustedData).

public SecuritySettings()

Fields

TrustedData

Default settings to use with trusted data.

public static readonly SecuritySettings TrustedData

Field Value

SecuritySettings

Remarks

This value is optimized for high performance assuming the data is trustworthy, and should not be used with untrusted data.

UntrustedData

Default settings to use when (de)serializing untrusted data.

public static readonly SecuritySettings UntrustedData

Field Value

SecuritySettings

Remarks

This value is optimized for security when processing untrusted data.

Properties

MaxObjectMemberCount

Gets the maximum number of members permitted in a single untyped JSON object (or dynamic object such as ExpandoObject) when deserializing.

public int MaxObjectMemberCount { get; init; }

Property Value

int

The default value is 1,000,000.

Remarks

This bounds memory and, for structures whose insertion cost grows with size, CPU when processing untrusted data. It applies only to the optional untyped and dynamic converters; strongly typed objects have a fixed member set.