wy471x opened a new pull request, #6897:
URL: https://github.com/apache/shenyu/pull/6897

   Use DataBufferUtils.join with maxSize to prevent OOM from large request 
bodies. Previously the full body was buffered into memory before the size check 
ran, allowing a multi-GB payload to exhaust heap. Now DataBufferLimitException 
is raised during buffering and returned as 413.
   
   <!-- Describe your PR here; e.g. Fixes #issueNo -->
   
   <!--
   Thank you for proposing a pull request. This template will guide you through 
the essential steps necessary for a pull request.
   -->
   Make sure that:
   
   - [X] You have read the [contribution 
guidelines](https://shenyu.apache.org/community/contributor-guide).
   - [X] You submit test cases (unit or integration tests) that back your 
changes.
   - [X] Your local test passed `./mvnw clean install 
-Dmaven.javadoc.skip=true`.
   
   ## Summary
   - Replaced DataBufferUtils.join(exchange.getRequest().getBody()) (no max 
size) with DataBufferUtils.join(exchange.getRequest().getBody(), 
MAX_REQUEST_BODY_SIZE_BYTES). This makes   
     Spring's DataBufferUtils enforce the 5 MB limit during buffering — a 
DataBufferLimitException is thrown immediately when the limit is exceeded, 
rather than buffering the entire   
     multi-GB body into heap first. Added 
.onErrorResume(DataBufferLimitException.class, ...) to catch that exception and 
return HTTP 413. Removed the now-redundant post-buffer size   
     check.
   - Added testRequestBodyExceedsMaxSize which mocks DataBufferUtils.join to 
return Mono.error(new DataBufferLimitException(...)) and asserts the response 
status is 413                
     PAYLOAD_TOO_LARGE.
   
   
   close [#6837](https://github.com/apache/shenyu/issues/6837)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to