Skip to content

fix(api): don't forward body headers to internal content requests - #3868

Merged
farnabaz merged 1 commit into
nuxt:mainfrom
devtechedge:fix/internal-fetch-body-headers
Oct 7, 2026
Merged

farnabaz merged 1 commit into
nuxt:mainfrom
devtechedge:fix/internal-fetch-body-headers

Conversation

@devtechedge

Copy link
Copy Markdown
Contributor

🔗 Linked issue

Resolves #3866

❓ Type of change

  • 🐞 Bug fix (a non-breaking change that fixes an issue)

📚 Description

fetchContent() copies the incoming request's headers onto the internal /__nuxt_content/<collection>/query call, including content-length.

Since 3.16.1, query.post.ts rejects bodies over MAX_BODY_BYTES based on that header, so any route that receives an upload larger than about 600 KB and then calls queryCollection(event, ...) gets a 413.

This drops the body framing headers (content-length, transfer-encoding, content-encoding, expect) before the internal fetch, so the guard measures the real SQL payload while cookies and auth headers are still forwarded.

The same applies to the sql_dump.txt GET from fetchDatabase(), which should not inherit a POST's body headers either.

Added test/unit/fetchContent.test.ts, which checks the headers passed to event.$fetch for both fetchQuery() and fetchDatabase(); it fails on main and passes with the change.

@vercel

vercel Bot commented Oct 7, 2026

Copy link
Copy Markdown

@devtechedge is attempting to deploy a commit to the Nuxt Team on Vercel.

A member of the Team first needs to authorize it.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 1a2f78a5-ac64-44ac-89b7-7911a3acd9a4
📥 Commits

Reviewing files that changed from the base of the PR and between 05a3074 and eb2e111.

📒 Files selected for processing (2)
  • src/runtime/internal/api.ts
  • test/unit/fetchContent.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

fetchContent now removes incoming content-length, transfer-encoding, content-encoding, and expect headers before building an internal request. Unit tests check header filtering and retention of cookie and authorization for fetchQuery and fetchDatabase. They also verify the endpoint calls, request method and body where applicable, and outgoing content-type.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to eb2e1

Internal query and database requests no longer inherit the incoming request’s body-framing headers while retaining authentication and the required content types. No merge-blocking risk remains in the reviewed changes.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main change: preventing body headers from being forwarded to internal content requests.
Description check ✅ Passed The description explains the body-header forwarding bug, its impact, the fix, and the tests added.
Linked Issues check ✅ Passed Issue #3866 requires the internal collection query to stop inheriting the incoming request’s body length. fetchContent() now clears content-length, transfer-encoding, content-encoding, and `ex…
Out of Scope Changes check ✅ Passed All changes support issue #3866. The additional removal of content-encoding and expect prevents other incoming body metadata from being applied to internal requests. The fetchDatabase() test ver…
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Warning

Some tools did not complete. Review the errors below.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

src/runtime/internal/api.ts

Parsing error: Unexpected token H3Event

test/unit/fetchContent.test.ts

Parsing error: Unexpected token {


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 7, 2026

Copy link
Copy Markdown
npm i https://pkg.pr.new/@nuxt/content@3868

commit: eb2e111

@farnabaz farnabaz left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, Thanks

@farnabaz
farnabaz merged commit ffa5ac3 into nuxt:main Oct 7, 2026
6 of 7 checks passed
@devtechedge

Copy link
Copy Markdown
Contributor Author

Thanks so much for the quick review and merge, Farnabaz!

It was genuinely fun tracing the 413 back to the new body size guard and seeing how internal /__nuxt_content requests were inheriting the upload's headers.

Your guard in #3851 made the edge case easy to reason about, and I learned a ton about how fetchContent() routes queries on the server. 🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3.16.1: queryCollection(event, …) fails with 413 "Request body too large" when the *incoming* request has a body over ~586 KB

2 participants