[
https://issues.apache.org/jira/browse/CAMEL-25463?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Claus Ibsen resolved CAMEL-25463.
---------------------------------
Resolution: Fixed
> camel-langchain4j-ingest: maxDocumentSize is checked only after the whole
> body is read
> --------------------------------------------------------------------------------------
>
> Key: CAMEL-25463
> URL: https://issues.apache.org/jira/browse/CAMEL-25463
> Project: Camel
> Issue Type: Improvement
> Components: camel-langchain4j
> Reporter: Jiri Ondrusek
> Assignee: Jiri Ondrusek
> Priority: Major
> Fix For: 4.23.0
>
>
> {{maxDocumentSize}} is documented as the protection against oversized
> (attacker-sized) payloads, but the producer measures a document only after
> reading it whole:
> * *text*: {{getBody(String.class)}}, then {{text.length()}} is compared; a
> file body gets no earlier check
> * *media*: {{getMandatoryBody(byte[].class)}}, then
> {{checkSize(bytes.length)}}; the {{CamelFileLength}} pre-check helps only
> when that header is present and trustworthy
> An oversized payload is rejected, but only once it is fully in the heap.
> Example, on a route without stream caching: a 10 MB InputStream body with a
> forged {{CamelFileLength=10}}, sent with
> {{modality=media&maxDocumentSize=100}}, fails with "exceeds maxDocumentSize
> (10000000 > 100 bytes)", so the whole body was read first.
> Stream caching, on by default and held in memory unless spooling is enabled,
> reads a stream body whole before the route reaches the endpoint. On such
> routes the payload is in the heap before the component sees it, so the size
> has to be limited at the consumer, or the stream spooled to disk.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)