Copilot commented on code in PR #7061:
URL: https://github.com/apache/shenyu/pull/7061#discussion_r4032737352
##########
shenyu-web/src/main/java/org/apache/shenyu/web/filter/FileSizeFilter.java:
##########
@@ -57,31 +58,40 @@ public class FileSizeFilter implements WebFilter {
private final int fileMaxSize;
+ /**
+ * The max number of bytes buffered while reading a multipart body, or -1
when the configured
+ * max size is not positive (in that case every multipart request is
rejected without buffering).
+ */
+ private final int maxInMemorySize;
+
private final List<HttpMessageReader<?>> messageReaders;
public FileSizeFilter(final int fileMaxSize) {
+ this.fileMaxSize = fileMaxSize;
+ this.maxInMemorySize = maxInMemorySize(fileMaxSize);
HandlerStrategies handlerStrategies = HandlerStrategies.builder()
- .codecs(configurer ->
configurer.defaultCodecs().maxInMemorySize(-1)).build();
+ .codecs(configurer ->
configurer.defaultCodecs().maxInMemorySize(this.maxInMemorySize)).build();
this.messageReaders = handlerStrategies.messageReaders();
- this.fileMaxSize = fileMaxSize;
}
@Override
@NonNull
public Mono<Void> filter(@NonNull final ServerWebExchange exchange,
@NonNull final WebFilterChain chain) {
MediaType mediaType =
exchange.getRequest().getHeaders().getContentType();
if (MediaType.MULTIPART_FORM_DATA.isCompatibleWith(mediaType)) {
+ // a non-positive max size rejects every multipart request, so its
body is not buffered at all
+ if (fileMaxSize <= 0) {
+ return payloadTooLarge(exchange, "The configured max size is "
+ fileMaxSize + "M");
+ }
ServerRequest serverRequest = ServerRequest.create(exchange,
messageReaders);
return serverRequest.bodyToMono(DataBuffer.class)
.flatMap(dataBuffer -> {
- if (dataBuffer.capacity() > Constants.BYTES_PER_MB *
fileMaxSize) {
- ServerHttpResponse response =
exchange.getResponse();
- response.setStatusCode(HttpStatus.BAD_REQUEST);
- Object error = ShenyuResultWrap.error(exchange,
ShenyuResultEnum.PAYLOAD_TOO_LARGE);
- LOG.info("The file size exceeds the limit. The
actual size is {}M , response:{}",
- dataBuffer.capacity() /
Constants.BYTES_PER_MB, error);
- return WebFluxResultUtils.result(exchange, error);
+ if (dataBuffer.capacity() > maxInMemorySize) {
+ final int actualSize = dataBuffer.capacity();
+ DataBufferUtils.release(dataBuffer);
+ return payloadTooLarge(exchange,
+ "The actual size is " + actualSize /
Constants.BYTES_PER_MB + "M");
}
Review Comment:
The size check uses `dataBuffer.capacity()`, which is the underlying buffer
capacity (allocation), not the actual number of readable bytes. For
pooled/growing buffers this can overcount and incorrectly reject (or log)
uploads; it should use `readableByteCount()` to reflect the real payload size.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]