fix(site): cap the sign-up body by bytes read, not Content-Length #155
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/site-signup-byte-cap"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The sign-up handler compared the Content-Length header to the 8 KiB limit,
treated a missing header as zero and then parsed the unbounded body with
request.formData(). A 65,610-byte form sent without the header was accepted
and stored.
The body is now read through a byte-counting reader that cancels the stream
and answers 413 as soon as it passes MAX_BODY_BYTES, before D1 is touched.
The form is parsed from the bytes that were read. Content-Length remains only
as an early rejection when it already declares a body over the limit.
Refs: VIK-1720
Co-Authored-By: Claude Opus 5.5 (1M context) noreply@anthropic.com
Content-Length is now only an early rejection; the body is counted as it streams and the stream is cancelled past 8 KiB. The form is parsed from the bytes read with the request's own Content-Type, so multipart boundaries still work.
Verified with
mise run verifyon the pinned toolchain (all gates passed).Ticket: https://vikunja.webgrip.dev/tasks/1720
🤖 Generated with Claude Code