Damus
Mitch Downey :pci: profile picture
Mitch Downey :pci:
@Mitch Downey :pci:
@nprofile1q... have you setup an "entity expansion limit" for RSS parsing before?

LLM advises me to set an entity expansion limit to avoid "XML bombs." I guess it means a feed is trying to waste your CPU resources.

It tells me 5,000 - 10,000 characters is sensible, but I saw what appears to be a valid (I think?) Arabic language feed from PI that exceeds our current 50,000 limit.

Any thoughts? I'm leaning towards keeping 50,000 as a limit and worrying about this if people complain about a feed missing.
1
Dave · 5w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqmvde59wznjjq4gt35rw26wfs0hznhpc2tsnnw3vj3m99gq8zv4pqppvfcp I just use file size. I’ve never heard the term entity expansion limit but I can deduce what it is from the name I think. That seems like a thing that a lot of xml parsers wouldn’t ...