Skip to content

Reject files above the upload size limit before sending any data - #6248

Open
bram-atmire wants to merge 1 commit into
DSpace:mainfrom
bram-atmire:upload-max-size-2848
Open

bram-atmire wants to merge 1 commit into
DSpace:mainfrom
bram-atmire:upload-max-size-2848

Conversation

@bram-atmire

Copy link
Copy Markdown
Member

References

Description

Files larger than the upload section's maxSize are now refused by the uploader when they are added, before any data is sent, and reported with the limit in the notification. Previously the whole file was transferred and the failure surfaced afterwards as a generic error.

Instructions for Reviewers

List of changes in this PR:

  • UploaderOptions.maxFileSize (bytes, optional). UploaderComponent registers a size filter that reads the option when a file is added, so a limit that arrives after initialisation is honoured, and reports a rejected file through onUploadError with status: 413, the same shape as the server's own rejection.
  • SubmissionFormComponent reads the upload section's configuration (/api/config/submissionuploads/<id>) and passes its maxSize to the uploader.
  • SubmissionUploadFilesComponent.onUploadError names the limit for a 413 (submission.sections.upload.upload-failed-max-size), or uses a generic too-large message when no limit is known; other failures keep the existing message.
  • MyDSpaceNewSubmissionComponent recognises a server-side 413 (mydspace.upload.upload-failed-max-size). No client-side limit is applied there because the collection, and therefore the upload configuration, is not known before the file is dropped; that open question from value of configuration option upload.max is not considered in submission form file upload #2848 stays open.
  • New i18n keys, including error.validation.filesize for the section error the backend now returns.
  • Specs for the uploader filter, the form wiring and the notifications.

How to test:

  1. Set upload.max = 1048576 in the backend local.cfg (or use Expose and enforce the submission upload size limit DSpace#13107, which reports the multipart limit by default). Open a submission's upload section and drop a 2 MB file: it is refused immediately with "The file is larger than the maximum upload size of 1 MB" and no request is sent.
  2. Drop a smaller file: it uploads as before.
  3. Without Expose and enforce the submission upload size limit DSpace#13107 and without upload.max, behaviour is unchanged.

Validation: npm run lint (0 errors), npm run check-circ-deps, and the specs for uploader.component, submission-form.component and submission-upload-files.component pass.

Checklist

  • My PR is created against the main branch of code (unless it is a backport or is fixing an issue specific to an older branch).
  • My PR is small in size (e.g. less than 1,000 lines of code, not including comments & specs/tests), or I have provided reasons as to why that's not possible.
  • My PR follows all coding best practices based on the Code Conventions Guide
  • My PR passes ESLint validation using npm run lint
  • My PR doesn't introduce circular dependencies (verified via npm run check-circ-deps)
  • My PR includes TypeDoc comments for all new (or modified) public methods and classes. It also includes TypeDoc for large or complex private methods.
  • My PR passes all specs/tests and includes new/updated specs or tests based on the Code Testing Guide.
  • My PR aligns with Accessibility guidelines if it makes changes to the user interface.
  • My PR uses i18n (internationalization) keys instead of hardcoded English text, to allow for translations.
  • My PR includes details on how to test it. I've provided clear instructions to reviewers on how to successfully test this fix or feature.
  • If my PR includes new libraries/dependencies (in package.json), I've made sure their licenses align with the DSpace BSD License based on the Licensing of Contributions documentation. (No new dependencies.)
  • If my PR includes new features or configurations, I've provided basic technical documentation in the PR itself.
  • If my PR fixes an issue ticket, I've linked them together.

https://claude.ai/code/session_01HtPYmqfFzg7fmZgovGWP5A

The submission form now passes the upload section's maxSize to the
uploader, which refuses larger files when they are added and reports
them as a 413 error instead of transferring the whole file first. The
notification names the limit. The MyDSpace drop zone and the submission
form also recognise a server-side 413.

Fixes DSpace#2848
Relates to DSpace/DSpace#13106.

Claude-Session: https://claude.ai/code/session_01HtPYmqfFzg7fmZgovGWP5A
@lgeggleston

Copy link
Copy Markdown
Contributor

Hi @bram-atmire, heads up that this is currently failing some tests (looks like just linting error). Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: 🙋 Needs Reviewers Assigned

Development

Successfully merging this pull request may close these issues.

value of configuration option upload.max is not considered in submission form file upload

2 participants