fix: enforce required file size limit on presigned upload route and R2 PutObjectCommand - #114
Merged
royalpinto007 merged 2 commits intoSep 10, 2026
Conversation
…2 PutObjectCommand
|
Welcome, @Basharameez, and thanks for your first pull request to agentpostmortem. A quick look at CONTRIBUTING.md covers how things are set up and run here. I'll review this shortly. Ask anything in the thread if something is unclear. |
|
And it's in. Thanks @Basharameez. Good, focused change. Exactly the kind of thing agentpostmortem needs. If agentpostmortem is useful to you, a star goes a long way. Happy to see more from you whenever you have the time. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Enforces mandatory
sizevalidation in the upload presign API schema and bindsContentLengthin the S3/R2PutObjectCommandpresigned URL generator to prevent arbitrary-sized file uploads.Problem
Previously,
sizewas an optional parameter inapp/api/upload/presign/route.ts, andgetPresignedUploadUrlinlib/r2/upload.tsdid not passContentLengthtoPutObjectCommand. Consequently, a client could request a presigned upload URL without specifying a file size, and upload an arbitrarily large file (bypassing the 5 MB server-side limit).Solution
schemainapp/api/upload/presign/route.tsto makesizerequired (z.number().min(1).max(MAX_SIZE_BYTES)).getPresignedUploadUrlinlib/r2/upload.tsto acceptcontentLength?: numberand bindContentLengthinPutObjectCommand.sizefrom the validated presign request payload togetPresignedUploadUrl.Testing
app/api/upload/presign/route.test.ts: Verified 400 Bad Request responses for missingsizeand oversizedsize(> 5 MB), 429 rate limiting, and successful URL generation with valid size.lib/r2/upload.test.ts: Verified thatContentLengthis properly set onPutObjectCommand.npx vitest run: All 16 test files (138 tests) passed.next lint: 0 ESLint warnings or errors.prettier: Formatting verified.Closes #100