[ENG-4059] Screen the beginning of an oversized Node body - #306
Merged
Merged
Conversation
The Node guards (`protection.node()` and the engine's Node middleware) now screen the first `maxBodyBytes` of a longer body, as the Fetch path does, and report the cap as a `body-cap` skip. The cut-off body is no longer exposed as `req.body`. The rule validator also requires a condition's `inclusive` to be a boolean, since any other value is read for its truthiness. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Efficient streaming body prefix reader with thorough UTF-8 handling. 🎯 Quality: 100% Elite · 📦 Size: Medium 🤖 Authorship: Agent-written — Claude Code, going by its own attribution. Whether a person read it is unknown; coding agents can call the 📈 This month: Your 161st PR — above team average · Averaging Excellent |
When something upstream has called `setEncoding()`, the Node body reader receives strings. They are now measured and retained as the bytes they encode, so the cap stays a byte cap, and a prefix the cap cuts inside a UTF-8 character ends before that character. A chunk the reader cannot use is read past and reported as a `read-failed` skip; the request continues unscreened and the body is not exposed as `req.body`. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Author
|
/review |
mariojgt
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two small changes to how request bodies and rule conditions are handled.
Oversized Node bodies.
protection.node()and the engine's Node middleware now behave like the Fetch path when a body is longer thanmaxBodyBytes:maxBodyBytesare screened, where before the body was not screened at all;body-capskip, throughcoverage()onnode()and through a newonSkipoption on the engine middleware;req.body. Before, the handler received a body that did not match the request.The limit is in bytes, including when something upstream switched the stream to text with
setEncoding(). A prefix the cap cuts partway through a UTF-8 character ends before that character. A chunk the reader cannot use (for example from an object-mode stream) is reported as aread-failedskip; the request continues unscreened and the body is not exposed. A body within the cap is handled as before.inclusivevalidation. The rule validator now rejects a condition whoseinclusiveis anything other than a boolean. That includes the string"false", which the engine would treat as true. The published rule contract artifacts are unchanged.Synthetic tests cover:
setEncoding('utf8' | 'latin1' | 'hex'), both within and past the cap, on both guards;req.bodylooks like after a cut-off body;inclusive, including inside a group.Validation: full suite (3,467 passed, 7 skipped), typecheck, build,
rule-contract:checkandcapabilities:check.🤖 Generated with Claude Code