Skip to content

Fix #448: Enforce /api/metadata upload limits and validate Content-Length - #451

Closed
marioalbu08 wants to merge 1 commit into
NovaCode37:mainfrom
marioalbu08:fix/upload-size-guard
Closed

marioalbu08 wants to merge 1 commit into
NovaCode37:mainfrom
marioalbu08:fix/upload-size-guard

Conversation

@marioalbu08

Copy link
Copy Markdown
Contributor

Summary

Resolves #448 by enforcing the 20MB upload limit on chunked uploads and hardening the Content-Length header parsing.

Changes

  • Modified check_upload_size in web/security.py to intercept non-numeric and negative Content-Length headers and return a clean HTTP 400 instead of causing an unhandled 500 ValueError.
  • Replaced the unbounded shutil.copyfileobj in web/app.py's _spool function with a chunked while True loop that reads 8192 bytes at a time.
  • The _spool loop now actively tracks bytes_written and aggressively deletes the temporary file and raises an HTTP 413 error if the payload exceeds MAX_UPLOAD_BYTES.
  • Added test_metadata_upload_size_guard_no_content_length and test_metadata_upload_invalid_content_length to tests/test_upload_size_guard.py using FastAPI's TestClient to verify the exact cutoff and HTTP responses.

Type of change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update

Testing

  • I have tested these changes locally
  • I have added/updated tests as needed

Screenshots

N/A

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Thanks for the first pull request here. CI needs a maintainer to approve the run before it starts, so it may sit for a bit before anything happens. pytest tests/ -q passing is the main thing I look at.

@github-actions github-actions Bot added the python Pull requests that update python code label Oct 1, 2026
@NovaCode37

Copy link
Copy Markdown
Owner

Thanks for this. #449 fixed the same issue about half an hour earlier and is merged now, so I am closing this one as a duplicate. The two were close: both chunk the copy and both fix the Content-Length parsing. #449 also removes the temp file when the write fails for any reason, not only when the size is exceeded, which is what tipped it.

To avoid this next time, leave a comment on the issue before you start; I assign within a day and nobody ends up doing the same work twice. There are plenty of open ones under the hacktoberfest label.

@NovaCode37 NovaCode37 closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

C:/Program Files/Git/api/metadata only checks upload size from the Content-Length header

2 participants