fix: stream cover uploads with a per-chunk size cap

The cover multipart path called Field::bytes(), buffering the entire field
into memory before parse_image checked max_file_bytes — an oversized cover
was fully allocated before rejection. Add read_capped/push_capped, which
reject with 413 as soon as the running total exceeds the cap (the offending
chunk is never copied in), and route both cover handlers and stage_image_part
through it.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
MechaCat02
2026-07-11 13:51:10 +02:00
parent 5b46eab73a
commit 7570524e5b
5 changed files with 75 additions and 15 deletions

View File

@@ -1,6 +1,6 @@
[package]
name = "mangalord"
version = "0.124.15"
version = "0.124.16"
edition = "2021"
default-run = "mangalord"