Skip to content

[Security] AST-12: Inconsistent recvWindow Documentation Between Spot and Futures #89

Description

@mefai-dev

AST-12: Inconsistent recvWindow Documentation Between Spot and Futures

Severity: INFO
Affected File(s): aster-finance-spot-api.md, aster-finance-futures-api.md

Description

Spot docs state max recvWindow is 60 seconds. Futures docs only recommend 5000ms without stating the maximum. Inconsistent documentation creates confusion for developers.

Impact

Developer confusion about the actual maximum recvWindow value for the futures API.

Recommended Fix

Add explicit maximum recvWindow documentation to the futures API docs, matching the spot docs format.


Methodology: Triple-verification static analysis -- each finding verified across three independent code review passes.
Researcher: Independent Security Researcher -- Mefai Security Team

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions