Jiri Ondrusek created CAMEL-25463:
-------------------------------------
Summary: camel-langchain4j-ingest: maxDocumentSize is checked only
after the whole body is read
Key: CAMEL-25463
URL: https://issues.apache.org/jira/browse/CAMEL-25463
Project: Camel
Issue Type: Improvement
Components: camel-langchain4j
Reporter: Jiri Ondrusek
Assignee: Jiri Ondrusek
{{maxDocumentSize}} is documented as the protection against oversized
(attacker-sized) payloads, but the producer measures a document only after
reading it whole:
* *text*: {{getBody(String.class)}}, then {{text.length()}} is compared; a file
body gets no earlier check
* *media*: {{getMandatoryBody(byte[].class)}}, then
{{checkSize(bytes.length)}}; the {{CamelFileLength}} pre-check helps only when
that header is present and trustworthy
An oversized payload is rejected, but only once it is fully in the heap.
Example, on a route without stream caching: a 10 MB InputStream body with a
forged {{CamelFileLength=10}}, sent with
{{modality=media&maxDocumentSize=100}}, fails with "exceeds maxDocumentSize
(10000000 > 100 bytes)", so the whole body was read first.
Stream caching, on by default and held in memory unless spooling is enabled,
reads a stream body whole before the route reaches the endpoint. On such routes
the payload is in the heap before the component sees it, so the size has to be
limited at the consumer, or the stream spooled to disk.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)