mirror of
https://github.com/ComposioHQ/composio.git
synced 2026-09-22 11:46:35 +08:00
9d0cb2cf89
## Summary AppSecure SEC-908 reported that remote files fetched from user-supplied URLs were read into memory with no size cap. The core SDK (`fileUtils.node.ts`, `RemoteFile.ts`, `ToolRouterSessionFileMount.ts`) and the Python SDK already stream through a 100 MiB limit. The CLI's tool-input upload path (`ts/packages/cli/src/services/tool-file-uploads.ts`) was the last remaining sink: `readFileFromUrl` still did `response.arrayBuffer()`, so a large or never-ending response could exhaust memory before the presigned upload was even requested. Fixes SEC-908 (internal tracker). ## Changes - `@composio/core` exports `readResponseBodyWithLimit` and `MAX_URL_UPLOAD_SIZE_BYTES`, next to the existing `assertSafeFileUploadPath` export, so downstream packages reuse the one bounded reader. - CLI `readFileFromUrl` uses it in place of `response.arrayBuffer()`; behaviour is unchanged below the cap. - Regression test: a response declaring a body above the cap is rejected before `createPresignedURL` is called. - Changeset for `@composio/core` (patch). `@composio/cli` is in the changeset ignore list. ## Type of change - [x] Bug fix - [ ] New feature - [ ] Refactor/Chore - [ ] Documentation - [ ] Breaking change ## How Has This Been Tested? ``` pnpm --filter @composio/core build pnpm --filter @composio/core exec vitest run test/utils/readResponseBody.test.ts Tests 4 passed (4) pnpm --filter @composio/cli exec vitest run test/src/services/tool-file-uploads.test.ts Tests 8 passed (8) pnpm exec prettier --check <touched files> pnpm exec oxlint <touched files> ``` `tsc --noEmit` on the CLI package reports the same pre-existing errors on `next` and none in the touched files. Node 24.17.0, pnpm 11.8.0 via mise. ## Screenshots (if applicable) ## Checklist - [x] I have read the Code of Conduct and this PR adheres to it - [x] I ran linters/tests locally and they passed - [x] I updated documentation as needed - [x] I added tests or explain why not applicable - [x] I added a changeset if this change affects published packages ## Additional context The other files AppSecure listed for this finding were already capped on `next` (core:ecd0861, 8a56383; python:54d07dc); this PR closes the residual. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Changesets
Hello and welcome! This folder has been automatically generated by @changesets/cli, a build tool that works
with multi-package repos, or single-package repos to help you version and publish your code. You can
find the full documentation for it in our repository
We have a quick list of common questions to get you started engaging with this project in our documentation