[ 
https://issues.apache.org/jira/browse/CAMEL-25463?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Claus Ibsen resolved CAMEL-25463.
---------------------------------
    Resolution: Fixed

> camel-langchain4j-ingest: maxDocumentSize is checked only after the whole 
> body is read
> --------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25463
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25463
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-langchain4j
>            Reporter: Jiri Ondrusek
>            Assignee: Jiri Ondrusek
>            Priority: Major
>             Fix For: 4.23.0
>
>
> {{maxDocumentSize}} is documented as the protection against oversized 
> (attacker-sized) payloads, but the producer measures a document only after 
> reading it whole:
> * *text*: {{getBody(String.class)}}, then {{text.length()}} is compared; a 
> file body gets no earlier check
> * *media*: {{getMandatoryBody(byte[].class)}}, then 
> {{checkSize(bytes.length)}}; the {{CamelFileLength}} pre-check helps only 
> when that header is present and trustworthy
> An oversized payload is rejected, but only once it is fully in the heap. 
> Example, on a route without stream caching: a 10 MB InputStream body with a 
> forged {{CamelFileLength=10}}, sent with 
> {{modality=media&maxDocumentSize=100}}, fails with "exceeds maxDocumentSize 
> (10000000 > 100 bytes)", so the whole body was read first.
> Stream caching, on by default and held in memory unless spooling is enabled, 
> reads a stream body whole before the route reaches the endpoint. On such 
> routes the payload is in the heap before the component sees it, so the size 
> has to be limited at the consumer, or the stream spooled to disk.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to