Reject files above the upload size limit before sending any data - #6248
Open
bram-atmire wants to merge 1 commit into
Open
bram-atmire wants to merge 1 commit into
bram-atmire wants to merge 1 commit into
Conversation
The submission form now passes the upload section's maxSize to the uploader, which refuses larger files when they are added and reports them as a 413 error instead of transferring the whole file first. The notification names the limit. The MyDSpace drop zone and the submission form also recognise a server-side 413. Fixes DSpace#2848 Relates to DSpace/DSpace#13106. Claude-Session: https://claude.ai/code/session_01HtPYmqfFzg7fmZgovGWP5A
This was referenced Sep 12, 2026
Contributor
|
Hi @bram-atmire, heads up that this is currently failing some tests (looks like just linting error). Thanks! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
References
maxSizeto reflect the effective limit (without it the check only applies whenupload.maxor amaxSizeis configured)Description
Files larger than the upload section's
maxSizeare now refused by the uploader when they are added, before any data is sent, and reported with the limit in the notification. Previously the whole file was transferred and the failure surfaced afterwards as a generic error.Instructions for Reviewers
List of changes in this PR:
UploaderOptions.maxFileSize(bytes, optional).UploaderComponentregisters a size filter that reads the option when a file is added, so a limit that arrives after initialisation is honoured, and reports a rejected file throughonUploadErrorwithstatus: 413, the same shape as the server's own rejection.SubmissionFormComponentreads the upload section's configuration (/api/config/submissionuploads/<id>) and passes itsmaxSizeto the uploader.SubmissionUploadFilesComponent.onUploadErrornames the limit for a 413 (submission.sections.upload.upload-failed-max-size), or uses a generic too-large message when no limit is known; other failures keep the existing message.MyDSpaceNewSubmissionComponentrecognises a server-side 413 (mydspace.upload.upload-failed-max-size). No client-side limit is applied there because the collection, and therefore the upload configuration, is not known before the file is dropped; that open question from value of configuration option upload.max is not considered in submission form file upload #2848 stays open.error.validation.filesizefor the section error the backend now returns.How to test:
upload.max = 1048576in the backendlocal.cfg(or use Expose and enforce the submission upload size limit DSpace#13107, which reports the multipart limit by default). Open a submission's upload section and drop a 2 MB file: it is refused immediately with "The file is larger than the maximum upload size of 1 MB" and no request is sent.upload.max, behaviour is unchanged.Validation:
npm run lint(0 errors),npm run check-circ-deps, and the specs foruploader.component,submission-form.componentandsubmission-upload-files.componentpass.Checklist
mainbranch of code (unless it is a backport or is fixing an issue specific to an older branch).npm run lintnpm run check-circ-deps)package.json), I've made sure their licenses align with the DSpace BSD License based on the Licensing of Contributions documentation. (No new dependencies.)https://claude.ai/code/session_01HtPYmqfFzg7fmZgovGWP5A