[
https://issues.apache.org/jira/browse/COUCHDB-3174?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15544564#comment-15544564
]
ASF GitHub Bot commented on COUCHDB-3174:
-----------------------------------------
GitHub user nickva opened a pull request:
https://github.com/apache/couchdb-chttpd/pull/143
Add max_document_size checking for multipart PUT requests
Previously multipart/related PUT requests didn't check maximum request
sizes.
This commit checks content-length and compares that with the maximum.
This means keeping the current "semantics" of max_document_size which
actually
means "max request size". But this makes the check more efficient and can
be done earlier in request processing time.
PR depends on https://github.com/apache/couchdb-couch/pull/201 make sure to
merge that one first if accepted.
Jira: COUCHDB-3174
You can merge this pull request into a Git repository by running:
$ git pull https://github.com/cloudant/couchdb-chttpd couchdb-3174
Alternatively you can review and apply these changes as the patch at:
https://github.com/apache/couchdb-chttpd/pull/143.patch
To close this pull request, make a commit to your master/trunk branch
with (at least) the following in the commit message:
This closes #143
----
commit 5d7170c472d2ca72d4a0dd41eb7ae4434266be7d
Author: Nick Vatamaniuc <[email protected]>
Date: 2016-10-04T06:58:32Z
Add max_document_size checking for multipart PUT requests
Previously multipart/related PUT requests didn't check maximum request
sizes.
This commit checks content-length and compares that with the maximum.
This means keeping the current "semantics" of max_document_size which
actually
means "max request size". But this makes the check more efficient and can
be done earlier in request processing time.
PR depends on https://github.com/apache/couchdb-couch/pull/201 make sure to
merge that one first if accepted.
Jira: COUCHDB-3174
----
> max_document_size setting can by bypassed by issuing multipart/related
> requests
> -------------------------------------------------------------------------------
>
> Key: COUCHDB-3174
> URL: https://issues.apache.org/jira/browse/COUCHDB-3174
> Project: CouchDB
> Issue Type: Bug
> Reporter: Nick Vatamaniuc
> Attachments: attach_large.py
>
>
> Testing how replicator handled small values of max_document_size parameter,
> discovered if user issues PUT requests which are multipart/related, then
> max_document_size setting is bypassed.
> Wireshark capture of a PUT with attachments request coming from replicator in
> a EUnit test I wrote. max_document_size was set to 10000 yet a 70k byte
> document with a 70k byte attachment was created.
> {code}
> PUT /eunit-test-db-147555017168185/doc0?new_edits=false HTTP/1.1
> Content-Type: multipart/related; boundary="e5d21d5fd988dc1c6c6e8911030213b3"
> Content-Length: 140515
> Accept: application/json
> --e5d21d5fd988dc1c6c6e8911030213b3
> Content-Type: application/json
> {"_id":"doc0","_rev":"1-40a6a02761aba1474c4a1ad9081a4c2e","x":"xxxx....
> ...xxxx","_revisions":{"start":1,"ids":["40a6a02761aba1474c4a1ad9081a4c2e"]},"_attachments":{"att1":{"content_type":"app/binary","revpos":1,"digest":"md5-u+COd6RLUd6BGz0wJyuZFg==","length":70000,"follows":true}}}
> --e5d21d5fd988dc1c6c6e8911030213b3
> Content-Disposition: attachment; filename="att1"
> Content-Type: app/binary
> Content-Length: 70000
> xxxxx....xxxxx
> --e5d21d5fd988dc1c6c6e8911030213b3--
> HTTP/1.1 201 Created
> {code}
> Here is a regular request which works as expected:
> {code}
> PUT /dbl/dl2 HTTP/1.1
> Content-Length: 100026
> Content-Type: application/json
> Accept: application/json
> {"_id": "dl2", "size": "xxxx...xxx"}
> HTTP/1.1 413 Request Entity Too Large
> {code}
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)