Skip to content

fix: add request body size limit to proxy - #7

Open
hobostay wants to merge 1 commit into
aattaran:mainfrom
hobostay:fix/proxy-body-size-limit
Open

fix: add request body size limit to proxy#7
hobostay wants to merge 1 commit into
aattaran:mainfrom
hobostay:fix/proxy-body-size-limit

Conversation

@hobostay

@hobostay hobostay commented May 4, 2026

Copy link
Copy Markdown

Summary

  • Adds a 50MB request body size limit to the model API proxy path in proxy/model-proxy.js
  • Returns HTTP 413 and destroys the connection when the limit is exceeded

Problem

The /_proxy/mode control endpoint already had a 1KB body size limit, but the main model API request path (/v1/messages) collected request body chunks into memory without any bound. A client (or a bug in the calling code) could send an arbitrarily large request body, causing the proxy Node.js process to consume unbounded memory and potentially crash.

Test plan

  • Normal usage still works: send a regular /v1/messages request through the proxy
  • Oversized request is rejected: send a >50MB body and verify 413 response

🤖 Generated with Claude Code

The proxy had a 1KB size limit on the control endpoint (/_proxy/mode)
but no limit on model API request bodies. A client could send an
arbitrarily large request, causing memory exhaustion in the proxy
process. Add a 50MB limit with a 413 response on overflow.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
g-roliveira added a commit to g-roliveira/deepclaude that referenced this pull request Aug 6, 2026
…parity

Summary of fixes and features applied from aattaran/deepclaude
issues and PRs, plus original improvements:

Model coverage (Issue aattaran#39):
- Add claude-fable-5, claude-opus-5, claude-sonnet-5 to MODEL_REMAP
- Tier-based _default fallback (fable/opus/sonnet/haiku) so new
  Claude models degrade predictably instead of silently routing
  to the wrong backend
- Warning log when model is forwarded unmapped

Proxy resilience (PR aattaran#18):
- proxyRes error handler — upstream TCP reset mid-response no
  longer crashes the entire proxy process
- proxyReq error after headers-sent: destroy response instead of
  injecting JSON into the SSE stream (which corrupted the parser)

Thinking-block continuity (PR aattaran#24):
- Drop top-level thinking/context_management on non-Anthropic
  routes instead of stripping all thinking blocks from history
- Fixes DeepSeek 400: "content[].thinking must be passed back"

Proxy in normal mode (PR aattaran#9):
- Default launch now starts the proxy; cost tracking and live
  /switch work in all sessions, not just --remote
- Use ANTHROPIC_API_KEY instead of ANTHROPIC_AUTH_TOKEN so
  subscription OAuth tokens are handled correctly

Body size limit (PR aattaran#7):
- 50 MB cap on /v1/messages request body, returns 413

Forward unknown args to claude (Issue aattaran#25):
- Bash: -- separator support for explicit passthrough
- PowerShell: ValueFromRemainingArguments captures unknown flags

PowerShell parity (PR aattaran#5, aattaran#8):
- --switch/-s parameter with backend name normalization
- try/finally ensures proxy cleanup on Ctrl+C/crash

Model [1m] suffix:
- All model names include [1m] token window hint so Claude Code
  doesn't assume 200k context and auto-compact prematurely

Project documentation:
- CLAUDE.md with architecture overview, proxy routing, SSE
  normalization, model remapping, and development conventions
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant