[
https://issues.apache.org/jira/browse/FILEUPLOAD-148?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#action_12531745
]
Jochen Wiedmann commented on FILEUPLOAD-148:
--------------------------------------------
> Point is to deny loading large files into memory from FileItem.get() method.
> Point is to deny loading large files into memory from FileItem.get() method.
That's what DiskFileItemFactory.setThreshold() gives you. It seems, you are not
using this property or are setting it to a non-sensible value.
> FileItemFactory.setMaxStringLength()
> ------------------------------------
>
> Key: FILEUPLOAD-148
> URL: https://issues.apache.org/jira/browse/FILEUPLOAD-148
> Project: Commons FileUpload
> Issue Type: New Feature
> Affects Versions: 1.2
> Reporter: Stepan Koltsov
>
> Need method
> FileItemFactory.setMaxStringLength(int limitInBytes)
> When this parameter is set, calling of FileItem.getString() when getSize()
> exceeds limitInBytes should throw Exception. This is required to avoid OOME
> in case of wrongly submitted forms (i. e. when bad guy puts big file into the
> form field "fileDescription").
> Or even better sizeThreshold should be used for this value.
--
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.