Reject Mojolicious-truncated request bodies before native routes dispatch
Categories
(bugzilla.mozilla.org :: General, defect, P2)
Tracking
()
People
(Reporter: Logan, Unassigned)
Details
(Keywords: bmo-triaged)
Attachments
(1 file)
Bug 1832783 handles request-body parser limits at the legacy CGI bridge. Native Mojolicious routes can still dispatch after the parser reaches max_message_size or max_buffer_size and marks the request as limit-exceeded, leaving controllers to process a truncated body. JSON consumers may decode incomplete content or handle incomplete parameters, producing misleading errors.
Add app-wide handling before native controller dispatch for request-body parser limit failures. Return HTTP 413 using the response format expected by the route, including API and CORS contracts; log only a privacy-safe route and limit reason; and do not execute the target controller. Preserve the existing fallback behavior for start-line and header limits.
Add focused HTTP coverage for at least one native JSON route and verify that under-limit requests continue to dispatch normally.
Related: bug 1832783.
Updated•2 months ago
|
Comment 1•4 days ago
|
||
(via GitHub webhook, authenticated as shared-secret)
Comment 2•21 hours ago
|
||
Authored by https://github.com/loganrosen
https://github.com/mozilla/bmo/commit/c8d7bc14f149038da70078b3bed8508f20fc3c44
[master] Bug 2059957 - Reject truncated request bodies before native endpoint dispatch
(via GitHub webhook, authenticated as shared-secret)
Description
•