wy471x opened a new pull request, #6897: URL: https://github.com/apache/shenyu/pull/6897
Use DataBufferUtils.join with maxSize to prevent OOM from large request bodies. Previously the full body was buffered into memory before the size check ran, allowing a multi-GB payload to exhaust heap. Now DataBufferLimitException is raised during buffering and returned as 413. <!-- Describe your PR here; e.g. Fixes #issueNo --> <!-- Thank you for proposing a pull request. This template will guide you through the essential steps necessary for a pull request. --> Make sure that: - [X] You have read the [contribution guidelines](https://shenyu.apache.org/community/contributor-guide). - [X] You submit test cases (unit or integration tests) that back your changes. - [X] Your local test passed `./mvnw clean install -Dmaven.javadoc.skip=true`. ## Summary - Replaced DataBufferUtils.join(exchange.getRequest().getBody()) (no max size) with DataBufferUtils.join(exchange.getRequest().getBody(), MAX_REQUEST_BODY_SIZE_BYTES). This makes Spring's DataBufferUtils enforce the 5 MB limit during buffering — a DataBufferLimitException is thrown immediately when the limit is exceeded, rather than buffering the entire multi-GB body into heap first. Added .onErrorResume(DataBufferLimitException.class, ...) to catch that exception and return HTTP 413. Removed the now-redundant post-buffer size check. - Added testRequestBodyExceedsMaxSize which mocks DataBufferUtils.join to return Mono.error(new DataBufferLimitException(...)) and asserts the response status is 413 PAYLOAD_TOO_LARGE. close [#6837](https://github.com/apache/shenyu/issues/6837) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
