Repository navigation
fix(api): don't forward body headers to internal content requests - #3868
Conversation
|
@devtechedge is attempting to deploy a commit to the Nuxt Team on Vercel. A member of the Team first needs to authorize it. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughfetchContent now removes incoming content-length, transfer-encoding, content-encoding, and expect headers before building an internal request. Unit tests check header filtering and retention of cookie and authorization for fetchQuery and fetchDatabase. They also verify the endpoint calls, request method and body where applicable, and outgoing content-type. Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Severity of issue fixed: Medium Merge Risk: ⚪ Minimal · up to Internal query and database requests no longer inherit the incoming request’s body-framing headers while retaining authentication and the required content types. No merge-blocking risk remains in the reviewed changes. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Warning Some tools did not complete. Review the errors below. 🔧 ESLint
src/runtime/internal/api.tsParsing error: Unexpected token H3Event test/unit/fetchContent.test.tsParsing error: Unexpected token { Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
commit: |
|
Thanks so much for the quick review and merge, Farnabaz! It was genuinely fun tracing the 413 back to the new body size guard and seeing how internal Your guard in #3851 made the edge case easy to reason about, and I learned a ton about how |
🔗 Linked issue
Resolves #3866
❓ Type of change
📚 Description
fetchContent()copies the incoming request's headers onto the internal/__nuxt_content/<collection>/querycall, includingcontent-length.Since 3.16.1,
query.post.tsrejects bodies overMAX_BODY_BYTESbased on that header, so any route that receives an upload larger than about 600 KB and then callsqueryCollection(event, ...)gets a 413.This drops the body framing headers (
content-length,transfer-encoding,content-encoding,expect) before the internal fetch, so the guard measures the real SQL payload while cookies and auth headers are still forwarded.The same applies to the
sql_dump.txtGET fromfetchDatabase(), which should not inherit a POST's body headers either.Added
test/unit/fetchContent.test.ts, which checks the headers passed toevent.$fetchfor bothfetchQuery()andfetchDatabase(); it fails onmainand passes with the change.