Follow-up from the review of #1117 (outbound broker-assigned Topic Alias).
Today the per-connection outbound alias table (client._outboundTopicAliases) is bounded only by the value the client advertises in its CONNECT Topic Alias Maximum (≤ 65535) × the number of distinct topics actually delivered. The inbound direction has a broker-side ceiling (the topicAliasMaximum option), but the outbound direction has no symmetric broker cap — an untrusted client can advertise 65535, subscribe to #, and drive its per-connection Map<topic, alias> toward 65535 entries. It's self-inflicted and bounded per connection, but across many connections it's a memory-amplification vector, and it's asymmetric with the inbound path.
Proposal
Add a broker option (e.g. outboundTopicAliasMaximum, default 0 = no broker cap, preserving current behaviour) and clamp the effective per-connection outbound maximum to min(clientAdvertised, brokerCap) in the connect handler — natural symmetry with the existing inbound topicAliasMaximum option.
Raised in the #1117 review thread on lib/handlers/connect.js; deferring to keep that PR focused (the feature is correct and safe as-is; this only adds an opt-in ceiling).
Follow-up from the review of #1117 (outbound broker-assigned Topic Alias).
Today the per-connection outbound alias table (
client._outboundTopicAliases) is bounded only by the value the client advertises in its CONNECTTopic Alias Maximum(≤ 65535) × the number of distinct topics actually delivered. The inbound direction has a broker-side ceiling (thetopicAliasMaximumoption), but the outbound direction has no symmetric broker cap — an untrusted client can advertise65535, subscribe to#, and drive its per-connectionMap<topic, alias>toward 65535 entries. It's self-inflicted and bounded per connection, but across many connections it's a memory-amplification vector, and it's asymmetric with the inbound path.Proposal
Add a broker option (e.g.
outboundTopicAliasMaximum, default0= no broker cap, preserving current behaviour) and clamp the effective per-connection outbound maximum tomin(clientAdvertised, brokerCap)in the connect handler — natural symmetry with the existing inboundtopicAliasMaximumoption.Raised in the #1117 review thread on
lib/handlers/connect.js; deferring to keep that PR focused (the feature is correct and safe as-is; this only adds an opt-in ceiling).