Unbounded Output
Medium
- Category
- Output Handling
- Confidence
- 60% confidence
- Finding
Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.
- Content
md - Each token row is one row; merge in `investmentId` and `aggregateProductId` from its parent investment entry - **`investmentId` is MANDATORY in every row** — users need it for `redeem`/`claim` (via `okx-defi-invest`) - `aggregateProductId` — show if present, otherwise `–` - Token Contract: show the **full contract address** without truncation; show `–` if native/empty - Rewards: show pending reward amount + symbol if present, `–` if none; for platform rewards show `Platform reward` - Type: map investType → Supply/Borrow/Stake/Farm/Pool etc; pending rewards row uses `Pending` - **Health rate**: show separately below the table with warning if `healthRate < 1.5`
