Skip to content

MQTT 5.0: add a broker-side cap for outbound Topic Alias allocation #1124

Description

@BenjaminDobler

Follow-up from the review of #1117 (outbound broker-assigned Topic Alias).

Today the per-connection outbound alias table (client._outboundTopicAliases) is bounded only by the value the client advertises in its CONNECT Topic Alias Maximum (≤ 65535) × the number of distinct topics actually delivered. The inbound direction has a broker-side ceiling (the topicAliasMaximum option), but the outbound direction has no symmetric broker cap — an untrusted client can advertise 65535, subscribe to #, and drive its per-connection Map<topic, alias> toward 65535 entries. It's self-inflicted and bounded per connection, but across many connections it's a memory-amplification vector, and it's asymmetric with the inbound path.

Proposal

Add a broker option (e.g. outboundTopicAliasMaximum, default 0 = no broker cap, preserving current behaviour) and clamp the effective per-connection outbound maximum to min(clientAdvertised, brokerCap) in the connect handler — natural symmetry with the existing inbound topicAliasMaximum option.

Raised in the #1117 review thread on lib/handlers/connect.js; deferring to keep that PR focused (the feature is correct and safe as-is; this only adds an opt-in ceiling).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions