mirror of
https://github.com/Routstr/routstrd.git
synced 2026-10-05 20:38:22 +00:00
- Bound findStringField recursion to maxDepth=10 so adversarially deep 402 bodies cannot cause runaway recursion. Real 402 bodies nest 3-4 levels; 10 is generous while bounding the worst case. - Add runtime shape checks with logger.warn() to all four monkey-patches (_handleErrorResponse, createProviderToken, topUp) so SDK API drift is noisy instead of silent. The topUp patch previously called .bind() without verifying the method exists — a real TypeError on SDK upgrade. - Thread logger into installProvider402BodyCapture for the new warning. - Tests: depth-limit edge cases (4-level match + 50-level no-crash) and three API-drift detection tests verifying warnings fire when SDK methods are missing.