Skip to content

Commit 962bb26

Browse files
committed
fix(sse): reject oversized event frames
1 parent 62273b2 commit 962bb26

1 file changed

Lines changed: 12 additions & 0 deletions

File tree

‎src/main/java/io/github/easy4j/hermes/api/HermesSseClient.java‎

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@
88
import io.github.easy4j.hermes.api.sse.SseConsumerException;
99
import io.github.easy4j.hermes.api.sse.SseEvent;
1010
import io.github.easy4j.hermes.api.sse.SseFrame;
11+
import io.github.easy4j.hermes.api.sse.SseProtocolException;
1112
import io.github.easy4j.hermes.api.sse.SseQueueSubscription;
1213
import io.github.easy4j.hermes.api.sse.SseSubscription;
1314
import io.github.easy4j.hermes.exception.HermesHttpException;
@@ -23,6 +24,7 @@
2324
import okhttp3.extension.logging.HttpLogLevel;
2425

2526
import java.io.IOException;
27+
import java.nio.charset.StandardCharsets;
2628
import java.util.Collections;
2729
import java.util.Map;
2830
import java.util.Objects;
@@ -287,6 +289,16 @@ public void onEvent(EventSource eventSource, String id, String type, String data
287289
return;
288290
}
289291
SseFrame frame = new SseFrame(id, type, data, System.currentTimeMillis());
292+
int frameBytes = data.getBytes(StandardCharsets.UTF_8).length;
293+
if (frameBytes > Math.max(1, config.getStreamMaxEventBytes())) {
294+
SseProtocolException failure = new SseProtocolException(frame,
295+
"Hermes SSE frame exceeds configured limit: " + frameBytes + " bytes");
296+
terminalSignal.set(true);
297+
finish(subscription);
298+
onError.accept(failure);
299+
return;
300+
}
301+
290302
SseEvent event;
291303
try {
292304
event = eventDecoder.decode(frame);

0 commit comments

Comments
 (0)