Skip to content

fix(interceptor): limit response error body size - #5942

Open
mcollina wants to merge 1 commit into
mainfrom
fix/response-error-body-limit
Open

mcollina wants to merge 1 commit into
mainfrom
fix/response-error-body-limit

Conversation

@mcollina

@mcollina mcollina commented Oct 1, 2026

Copy link
Copy Markdown
Member

This relates to...

Hardening interceptors.responseError() against retaining arbitrarily large decoded error bodies.

Rationale

responseError automatically decodes JSON and plain-text error responses so they can be attached to ResponseError.body. Those bodies previously had no interceptor-specific retention limit.

Changes

Features

  • Add a maxSize option to interceptors.responseError().
  • Default the retained error body to 1 MiB; maxSize: 0 restores unlimited retention.
  • Add ResponseError.bodyTruncated so callers can detect a retained prefix.

Bug Fixes

  • Bound JSON and plain-text error body retention by decoded input bytes.
  • Keep truncated JSON as a string rather than parsing an incomplete document.
  • Preserve bounded behavior when responseError is composed after decompression.

Breaking Changes and Deprecations

Error bodies larger than 1 MiB are truncated by default. Applications that intentionally consume larger error bodies can configure a larger maxSize or set it to 0 to retain the previous unlimited behavior.

Status

Validation

  • npm run test:unit — 1,568 passed, 5 skipped
  • npx borp -p "test/interceptors/response-error.js" — 14 passed
  • npm run test:typescript
  • npm run lint
  • git diff --check

Signed-off-by: Matteo Collina <hello@matteocollina.com>
@codecov-commenter

codecov-commenter commented Oct 1, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 94.59459% with 4 lines in your changes missing coverage. Please review.
✅ Project coverage is 86.10%. Comparing base (7bc9dd6) to head (afbf59d).
⚠️ Report is 9 commits behind head on main.

Files with missing lines Patch % Lines
lib/interceptor/response-error.js 94.44% 4 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #5942      +/-   ##
==========================================
- Coverage   94.04%   86.10%   -7.95%     
==========================================
  Files         110      115       +5     
  Lines       40252    45620    +5368     
==========================================
+ Hits        37856    39282    +1426     
- Misses       2396     6338    +3942     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mcollina

mcollina commented Oct 2, 2026

Copy link
Copy Markdown
Member Author

CI note: the four failing Node.js 22 jobs all abort in the unrelated test/http2-request-never-settles.js test with Node's Assertion failed: onread->IsFunction(). I reran the failed jobs and got the same result. The same Node.js 22 jobs are currently failing on unrelated PRs #5941 and #5943, while this PR's Node.js 24–26 matrix, lint, type tests, CodeQL, fuzzing, and benchmarks pass.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants