Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Rust Server] Allow configuration of multipart/form attachment size limit #19371

Merged

Conversation

richardwhiuk
Copy link
Contributor

@richardwhiuk richardwhiuk commented Aug 16, 2024

multipart 0.14+ imposes a 8MB size limit on multipart/form bodies - so we regressed support for > 8MB when we upgraded to multipart 0.14 a while back.

This change allows that limit to be configured at a server scope. The default is left as is, as removing the limit, or substantially increasing it, may present a Denial of Service attack risk.

This also improves error messages produced when handling multipart/form bodies.

PR checklist

  • Read the contribution guidelines.
  • Pull Request title clearly describes the work in the pull request and Pull Request description provides details about how to validate the work. Missing information here may result in delayed response from the community.
  • Run the following to build the project and update samples:
    ./mvnw clean package 
    ./bin/generate-samples.sh ./bin/configs/*.yaml
    ./bin/utils/export_docs_generators.sh
    
    (For Windows users, please run the script in Git BASH)
    Commit all changed files.
    This is important, as CI jobs will verify all generator outputs of your HEAD commit as it would merge with master.
    These must match the expectations made by your contribution.
    You may regenerate an individual generator by passing the relevant config(s) as an argument to the script, for example ./bin/generate-samples.sh bin/configs/java*.
    IMPORTANT: Do NOT purge/delete any folders/files (e.g. tests) when regenerating the samples as manually written tests may be removed.
  • File the PR against the correct branch: master (upcoming 7.6.0 minor release - breaking changes with fallbacks), 8.0.x (breaking changes without fallbacks)
  • If your PR is targeting a particular programming language, @mention the technical committee members, so they are more likely to review the pull request.

Rust Technical Committee: @frol @farcaller @paladinzh @jacob-pro

richardwhiuk and others added 2 commits August 16, 2024 16:42
…imit

multipart 0.14+ imposes a 8MB size limit on multipart/form bodies.

This allows that limit to be configured. The default is left as is.

This also improves error messages produced when handling multipart/form bodies.
@wing328 wing328 removed the rust label Aug 17, 2024
@wing328 wing328 merged commit 0a5c997 into OpenAPITools:master Aug 17, 2024
19 checks passed
@wing328 wing328 added this to the 7.8.0 milestone Aug 17, 2024
@richardwhiuk richardwhiuk deleted the rust-server-multipart-size-limit branch August 19, 2024 10:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants