Closed Bug 2059957 Opened 2 months ago Closed 21 hours ago

Reject Mojolicious-truncated request bodies before native routes dispatch

Categories

(bugzilla.mozilla.org :: General, defect, P2)

Tracking

()

RESOLVED FIXED

People

(Reporter: Logan, Unassigned)

Details

(Keywords: bmo-triaged)

Attachments

(1 file)

Bug 1832783 handles request-body parser limits at the legacy CGI bridge. Native Mojolicious routes can still dispatch after the parser reaches max_message_size or max_buffer_size and marks the request as limit-exceeded, leaving controllers to process a truncated body. JSON consumers may decode incomplete content or handle incomplete parameters, producing misleading errors.

Add app-wide handling before native controller dispatch for request-body parser limit failures. Return HTTP 413 using the response format expected by the route, including API and CORS contracts; log only a privacy-safe route and limit reason; and do not execute the target controller. Preserve the existing fallback behavior for start-line and header limits.

Add focused HTTP coverage for at least one native JSON route and verify that under-limit requests continue to dispatch normally.

Related: bug 1832783.

Keywords: bmo-triaged
Priority: -- → P2

Authored by https://github.com/loganrosen
https://github.com/mozilla/bmo/commit/c8d7bc14f149038da70078b3bed8508f20fc3c44
[master] Bug 2059957 - Reject truncated request bodies before native endpoint dispatch

(via GitHub webhook, authenticated as shared-secret)

Status: NEW → RESOLVED
Closed: 21 hours ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: