Skip to content

fix(decode): reject requests with trailing non-whitespace data in DecodeJSON - #68

Closed
AdamMagued wants to merge 1 commit into
go-chi:masterfrom
AdamMagued:fix-decode-json-trailing-garbage
Closed

AdamMagued wants to merge 1 commit into
go-chi:masterfrom
AdamMagued:fix-decode-json-trailing-garbage

Conversation

@AdamMagued

Copy link
Copy Markdown

Fixes #42

Problem

DecodeJSON in render/decoder.go used json.NewDecoder(r).Decode(v) without checking for trailing data after decoding the target object. Because json.Decoder is designed for streaming JSON values, trailing non-whitespace garbage or secondary JSON payloads (such as "{}\n some garbage data") were silently accepted.

Solution

After decoding the target value into v, verify that the stream has reached io.EOF by checking the result of dec.Decode(&struct{}{}). If trailing non-whitespace data or extra JSON objects exist, return the error. Payloads with trailing whitespace continue to be accepted.

Testing

Added tests in render/decoder_test.go covering:

  • Valid JSON object decoding
  • Valid JSON with trailing whitespace (spaces, tabs, newlines)
  • Rejection of trailing garbage data (regression test for DecodeJSON accepts "{}\n some garbage data" incorrectly #42)
  • Rejection of trailing secondary JSON values and delimiters
  • Integration with DefaultDecoder on HTTP request payloads

…odeJSON

json.Decoder.Decode reads a single JSON value and leaves the decoder stream positioned after that value. Previously, DecodeJSON returned immediately after the first Decode call without verifying that the stream had ended, causing requests with trailing non-whitespace data or extra JSON values after the valid payload to be accepted.

Ensure no trailing non-whitespace data exists after decoding the target value by checking for io.EOF on a subsequent decode call. Add unit and regression tests for DecodeJSON and DefaultDecoder.

Fixes go-chi#42
@AdamMagued

Copy link
Copy Markdown
Author

Closing in favor of earlier PR #63 to keep the review queue clean.

@AdamMagued AdamMagued closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DecodeJSON accepts "{}\n some garbage data" incorrectly

1 participant