Security
Use this page when a Rust reader accepts bytes from outside the application's trust boundary. Fory reconstructs application values; it does not authenticate the sender, protect transport integrity, or decide whether a valid value is authorized for a business operation.
Application boundary
Before deserialization:
- Authenticate the sender and protect message integrity at the transport or storage layer.
- Enforce request or file size, timeout, and concurrency limits outside Fory.
- Register only the application types the endpoint accepts and configure the reader before its first root operation.
- Validate the deserialized value against application authorization and domain rules before use.
Built-in safeguards
Security-related configuration:
- Register application structs and trait-object implementations before deserializing untrusted payloads.
- Use
max_dyn_depth(...)to reject unexpectedly deep dynamic object graphs. - Keep
max_graph_memory_bytes(...)at the fixed128 MiBdefault for most inputs, or set a positive byte gate for trusted workloads with different legitimate collection/map/struct sizes. - Keep
max_unbacked_container_items(...)at8192unless trusted compact codecs require a larger root allowance. Zero rejects every unbacked item. - Keep the remote schema metadata limits at their defaults unless the data is not malicious and a trusted peer sends larger metadata or many schema versions.
- Prefer concrete typed fields over
dyn Anyor broad trait-object fields for untrusted input.
Verification
Add negative tests for the boundary as well as normal round trips. Verify that the configured reader rejects unexpected application types, excessive nesting, resource-limit violations, and malformed input. After a failed read, verify that a valid root can still be read with the same Fory instance.
See Configuration for the complete option reference and Type Registration for the Fory registration API.