Skip to content

Enforce upload size limit on /api/metadata body and harden Content-Length parsing - #449

Merged
NovaCode37 merged 1 commit into
NovaCode37:mainfrom
emiribrahimm:fix/issue-448
Oct 1, 2026
Merged

NovaCode37 merged 1 commit into
NovaCode37:mainfrom
emiribrahimm:fix/issue-448

Conversation

@emiribrahimm

Copy link
Copy Markdown
Contributor

Fixes #448

Problem

/api/metadata only checked the Content-Length header for upload size, so chunked uploads without that header could exceed the limit. Additionally, check_upload_size raised an unhandled ValueError (500) on non-numeric or negative Content-Length values.

Fix

Replaced the unbounded shutil.copyfileobj in the /api/metadata spool step with a chunked read that raises 413 once MAX_UPLOAD_BYTES is exceeded and removes the partial temp file on failure. Made check_upload_size return HTTP 400 for non-numeric or negative Content-Length instead of propagating ValueError.

Tests

  • Added a regression test in tests/test_upload_size_guard.py that fails before this change and passes after it.
  • The existing test suite passes locally.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Thanks for the first pull request here. CI needs a maintainer to approve the run before it starts, so it may sit for a bit before anything happens. pytest tests/ -q passing is the main thing I look at.

@github-actions github-actions Bot added the python Pull requests that update python code label Oct 1, 2026
@NovaCode37
NovaCode37 merged commit 3c1c0ad into NovaCode37:main Oct 1, 2026
9 checks passed
@NovaCode37 NovaCode37 added the hacktoberfest-accepted Counts toward Hacktoberfest label Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hacktoberfest-accepted Counts toward Hacktoberfest python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

C:/Program Files/Git/api/metadata only checks upload size from the Content-Length header

2 participants