89799969 opened a new pull request, #5145: URL: https://github.com/apache/rocketmq-dashboard/pull/5145
### Which Issue(s) This PR Fixes - Fixes #4640 ### Brief Description `Client.request` in `rmqctl/internal/studio/client.go` read the Studio API response body with an unbounded `io.ReadAll`. Every Studio response is a small JSON envelope, so nothing justified buffering an arbitrary stream before validation. - Add a 64 MiB cap (`maxResponseBytes`) and read through `io.LimitReader`. - Fail with a clear `studio response exceeds N bytes` error once the cap is exceeded. - Keep the limit on `Client` so tests can inject a small value without changing production defaults. ### How Did You Test This Change? ``` cd rmqctl && go test ./internal/studio -count=1 -v ``` All existing studio tests plus the new cases pass: - `TestReadBounded` — accepts a body at the limit, rejects one byte over - `TestRequestRejectsOversizedStudioResponse` — `Client.request` returns the size-cap error - `TestRequestAcceptsNormalStudioEnvelope` — normal small envelopes still decode ### Checklist - [x] One coherent change; unrelated modifications are not bundled in - [x] Commit subject follows Conventional Commits (`feat:` / `fix:` / `refactor:` / `chore:` / `docs:` / `perf:`) - [x] Tests added or updated for non-trivial changes, test methods named `...Test` - [ ] New UI text has both Chinese and English entries under `web/src/i18n/` (N/A — CLI only) - [x] Architecture constraints stay green (`mvn test` runs the ArchUnit checks) (N/A — Go-only change; no Java) - [x] New source files carry the ASF license header (no new source files) - [x] Documentation touched where behaviour changed (README / `docs/` / in-app help) (N/A — internal client bound) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
