logoalt Hacker News

spooneybargerlast Sunday at 7:50 PM1 replyview on HN

Most servers implement a heuristic for "query cost/complexity" with a configurable max. At the time the query is parsed, its cost is determined based on the heuristic and if it is over the max, the query is rejected.


Replies

lll-o-llllast Sunday at 9:46 PM

Which would be fine for internal facing, but it doesn’t sound like it would be enough in an adversarial context?

show 1 reply