89799969 opened a new pull request, #5145:
URL: https://github.com/apache/rocketmq-dashboard/pull/5145

   ### Which Issue(s) This PR Fixes
   
   - Fixes #4640
   
   ### Brief Description
   
   `Client.request` in `rmqctl/internal/studio/client.go` read the Studio API 
response body with an unbounded `io.ReadAll`. Every Studio response is a small 
JSON envelope, so nothing justified buffering an arbitrary stream before 
validation.
   
   - Add a 64 MiB cap (`maxResponseBytes`) and read through `io.LimitReader`.
   - Fail with a clear `studio response exceeds N bytes` error once the cap is 
exceeded.
   - Keep the limit on `Client` so tests can inject a small value without 
changing production defaults.
   
   ### How Did You Test This Change?
   
   ```
   cd rmqctl && go test ./internal/studio -count=1 -v
   ```
   
   All existing studio tests plus the new cases pass:
   
   - `TestReadBounded` — accepts a body at the limit, rejects one byte over
   - `TestRequestRejectsOversizedStudioResponse` — `Client.request` returns the 
size-cap error
   - `TestRequestAcceptsNormalStudioEnvelope` — normal small envelopes still 
decode
   
   ### Checklist
   
   - [x] One coherent change; unrelated modifications are not bundled in
   - [x] Commit subject follows Conventional Commits (`feat:` / `fix:` / 
`refactor:` / `chore:` / `docs:` / `perf:`)
   - [x] Tests added or updated for non-trivial changes, test methods named 
`...Test`
   - [ ] New UI text has both Chinese and English entries under `web/src/i18n/` 
(N/A — CLI only)
   - [x] Architecture constraints stay green (`mvn test` runs the ArchUnit 
checks) (N/A — Go-only change; no Java)
   - [x] New source files carry the ASF license header (no new source files)
   - [x] Documentation touched where behaviour changed (README / `docs/` / 
in-app help) (N/A — internal client bound)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to