{"record":{"id":"f558213540c14252","repo":"ruvnet/ruflo","slug":"key-exceeds-maximum-nesting-depth-of-max-nesting","errorCode":null,"errorMessage":"Key exceeds maximum nesting depth of ${MAX_NESTING_DEPTH}","messagePattern":"Key exceeds maximum nesting depth of (.+?)","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/mcp-tools/config-tools.ts","lineNumber":105,"sourceCode":"}\n\nconst DANGEROUS_KEYS = new Set(['__proto__', 'constructor', 'prototype']);\n\nfunction filterDangerousKeys(obj: Record<string, unknown>): Record<string, unknown> {\n  const filtered: Record<string, unknown> = {};\n  for (const [key, value] of Object.entries(obj)) {\n    if (!DANGEROUS_KEYS.has(key)) {\n      filtered[key] = value;\n    }\n  }\n  return filtered;\n}\n\nfunction setNestedValue(obj: Record<string, unknown>, key: string, value: unknown): void {\n  const MAX_NESTING_DEPTH = 10;\n  const parts = key.split('.');\n  if (parts.length > MAX_NESTING_DEPTH) {\n    throw new Error(`Key exceeds maximum nesting depth of ${MAX_NESTING_DEPTH}`);\n  }\n  for (const part of parts) {\n    if (DANGEROUS_KEYS.has(part)) {\n      throw new Error(`Dangerous key segment rejected: ${part}`);\n    }\n  }\n  let current = obj;\n  for (let i = 0; i < parts.length - 1; i++) {\n    const part = parts[i];\n    if (!(part in current) || typeof current[part] !== 'object') {\n      current[part] = {};\n    }\n    current = current[part] as Record<string, unknown>;\n  }\n  current[parts[parts.length - 1]] = value;\n}\n\nexport const configTools: MCPTool[] = [","sourceCodeStart":87,"sourceCodeEnd":123,"githubUrl":"https://github.com/ruvnet/ruflo/blob/fa13ee4ad60ac2090b1480656eb233521790d640/v3/@claude-flow/cli/src/mcp-tools/config-tools.ts#L87-L123","documentation":"Thrown by setNestedValue() in config-tools.ts:105, used by the config_set tool. Keys are dotted paths ('a.b.c'); after splitting on '.', a key with more than MAX_NESTING_DEPTH = 10 segments is rejected before any object mutation. This bounds recursion and keeps the config tree from being arbitrarily deepened by a single call.","triggerScenarios":"Calling config_set with a dotted key of 11+ segments, e.g. 'integrations.github.webhooks.events.push.filters.branch.pattern' — split('.') yields 11 parts and throws. The limit counts every segment including the final leaf key.","commonSituations":"Auto-generating keys from deep JSON paths or feature-flag hierarchies; mistaking a dotted hostname or semver string ('cdn.v2.example.com') for a shallow key; porting a deeply nested YAML config into flat dotted keys verbatim.","solutions":["Flatten the key to at most 10 segments: move the deepest levels into the value ('a.b.c.d': {remaining: 'nesting'})","Set intermediate objects in two calls — write the deep subtree as a JSON value at a shallower key","Serialize very deep structures to a JSON string value stored at a shallow key"],"exampleFix":"// before: 11 segments\nawait callTool('config_set', {\n  key: 'integrations.github.webhooks.events.push.filters.branch.pattern',\n  value: 'main',\n}); // throws: Key exceeds maximum nesting depth of 10\n\n// after: store the deep subtree as a value at a shallow key\nawait callTool('config_set', {\n  key: 'integrations.github.webhooks',\n  value: { events: { push: { filters: { branch: { pattern: 'main' } } } } },\n});","handlingStrategy":"validation","validationCode":"const MAX_DEPTH = 10;\nfunction isAcceptableKey(key: string): boolean {\n  const parts = key.split('.');\n  return parts.length <= MAX_DEPTH && parts.every((p) => p && !['__proto__', 'constructor', 'prototype'].includes(p));\n}\nif (!isAcceptableKey(key)) throw new TypeError('config key too deep or contains a reserved segment');","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Keep config keys shallow by design — store deep subtrees as JSON values instead of long dotted paths","If keys are generated from object paths, cap the walk depth at generation time"],"tags":["validation","config","nesting-limit","mcp"],"backgroundTag":"config-depth-limit-exceeded","analyzedSha":"fa13ee4ad60ac2090b1480656eb233521790d640","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}