Skip to content

Flag cap-cut deflate bodies, bound encoding layers, add max_body_size to BatchConfig - #114

Merged
liquidsec merged 1 commit into
devfrom
fix-body-decode
Oct 5, 2026
Merged

liquidsec merged 1 commit into
devfrom
fix-body-decode

Conversation

@liquidsec

Copy link
Copy Markdown
Collaborator

Fixes #90, #93 and #94. All three are about how max_body_size and decoding bound what a response can cost.

New tests: Python tests for both deflate flavors hitting the cap and for max_body_size in a batch, and a Rust unit test for the layer limit.

… to BatchConfig

A deflate body cut short by max_body_size read as cleanly decoded, since
neither deflate flavor has a trailer the decoder checks. A body whose read
stopped at the cap is now flagged either way.

The number of Content-Encoding layers came straight from the header, so a
response could make the client run thousands of near full-size decode
passes. At most three are undone now, and anything past that is flagged.

BatchConfig had no max_body_size, so every batch response was stuck at the
10MB default even though the README lists it. It is now a constructor
kwarg like the others.

Fixes #90
Fixes #93
Fixes #94
@liquidsec
liquidsec requested a review from singlerider October 5, 2026 15:20
@liquidsec liquidsec self-assigned this Oct 5, 2026
@liquidsec
liquidsec merged commit 9e682db into dev Oct 5, 2026
15 checks passed
@liquidsec
liquidsec deleted the fix-body-decode branch October 5, 2026 20:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants