rpc: enforce rpc api module availability

Fixes #20467

Signed-off-by: meows <b5c6@protonmail.com>
This commit is contained in:
meows 2019-12-18 08:44:41 -06:00
parent 6ae9dc15cc
commit 0572ca3c61
No known key found for this signature in database
GPG key ID: 5786AEA5C8D5A520

View file

@ -18,6 +18,7 @@ package rpc
import ( import (
"net" "net"
"strings"
"github.com/ethereum/go-ethereum/log" "github.com/ethereum/go-ethereum/log"
) )
@ -27,6 +28,29 @@ func StartHTTPEndpoint(endpoint string, apis []API, modules []string, cors []str
// Generate the whitelist based on the allowed modules // Generate the whitelist based on the allowed modules
whitelist := make(map[string]bool) whitelist := make(map[string]bool)
for _, module := range modules { for _, module := range modules {
apiExists := false
for _, api := range apis {
if module == api.Namespace {
apiExists = true
break
}
}
if !apiExists {
log.Crit("invalid api module", "module", module, "available", func() string {
available := []string{}
outer:
for _, api := range apis {
// Only include unique api names
for _, av := range available {
if av == api.Namespace {
continue outer
}
}
available = append(available, api.Namespace)
}
return strings.Join(available, ",")
}())
}
whitelist[module] = true whitelist[module] = true
} }
// Register all the APIs exposed by the services // Register all the APIs exposed by the services