Jiri Ondrusek created CAMEL-25463:
-------------------------------------

             Summary: camel-langchain4j-ingest: maxDocumentSize is checked only 
after the whole body is read
                 Key: CAMEL-25463
                 URL: https://issues.apache.org/jira/browse/CAMEL-25463
             Project: Camel
          Issue Type: Improvement
          Components: camel-langchain4j
            Reporter: Jiri Ondrusek
            Assignee: Jiri Ondrusek


{{maxDocumentSize}} is documented as the protection against oversized 
(attacker-sized) payloads, but the producer measures a document only after 
reading it whole:

* *text*: {{getBody(String.class)}}, then {{text.length()}} is compared; a file 
body gets no earlier check
* *media*: {{getMandatoryBody(byte[].class)}}, then 
{{checkSize(bytes.length)}}; the {{CamelFileLength}} pre-check helps only when 
that header is present and trustworthy

An oversized payload is rejected, but only once it is fully in the heap. 
Example, on a route without stream caching: a 10 MB InputStream body with a 
forged {{CamelFileLength=10}}, sent with 
{{modality=media&maxDocumentSize=100}}, fails with "exceeds maxDocumentSize 
(10000000 > 100 bytes)", so the whole body was read first.

Stream caching, on by default and held in memory unless spooling is enabled, 
reads a stream body whole before the route reaches the endpoint. On such routes 
the payload is in the heap before the component sees it, so the size has to be 
limited at the consumer, or the stream spooled to disk.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to