Skip to content

[v3.8.50] fix(api): defer media body size limits to providers - #8843

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.50from
artickc:fix/media-body-size-floor
Aug 4, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.50from
artickc:fix/media-body-size-floor

Conversation

@artickc

@artickc artickc commented Jul 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Stop OmniRoute from returning its hardcoded 413 PAYLOAD_TOO_LARGE response for /api/v1/images/*, /api/v1/videos/*, and /api/v1/providers/{provider}/images/generations.
  • Resolve direct media routes and the narrowly matched provider-specific image-generation route to an unbounded guard sentinel so both the global Content-Length admission check and the streamed image-edit reader defer size validation to the selected provider.
  • Keep the existing finite limits unchanged for chat/responses, audio, files, backups, and every other route.
  • Add the required changelog fragment for the user-visible fix.

The reported failure happened before provider dispatch in src/shared/middleware/bodySizeGuard.ts:

{"error":{"message":"Request body too large. Maximum allowed: 10 MB","type":"payload_too_large","code":"PAYLOAD_TOO_LARGE"}}

Base64 media adds roughly 33% envelope overhead and provider limits vary by model, so OmniRoute's global 10 MB default was not an appropriate authority for image/video payloads.

Related Issues

Validation

  • Focused tests: node --import tsx/esm --test tests/unit/body-size-guard.test.ts tests/unit/image-generation-route.test.ts — 34/34 passed
  • npm run lint — passed
  • npm run typecheck:core — passed
  • npm run check:changelog-integrity — passed
  • Production-code changes include updated automated tests in this PR
  • Refreshed GitHub CI: DAST, all four unit shards, Fast Quality/typechecks, lint, Vitest, docs, changelog integrity, and Semgrep passed; the non-blocking advisory Next build was canceled by a runner shutdown while the workflow concluded success

Tests Added Or Updated

  • tests/unit/body-size-guard.test.ts
    • asserts direct image generation, image edits, image upscale, video generation, and provider-specific image generation resolve to the unbounded media limit;
    • asserts even Number.MAX_SAFE_INTEGER in Content-Length cannot produce OmniRoute's media PAYLOAD_TOO_LARGE response;
    • exercises the streamed image-edit reader with the same declaration;
    • verifies adjacent provider chat, embeddings, and lookalike paths remain bounded;`n - preserves existing tests that verify finite non-media limits still reject oversized requests.
  • tests/unit/image-generation-route.test.ts
    • replaces the old 413 contract with a route-level assertion that a huge declared image-edit body reaches ordinary request validation;
    • verifies the response is the expected missing-prompt 400 and does not contain a payload-size error.

Coverage Notes

The focused suites cover direct media and provider-specific image-generation matching in src/shared/middleware/bodySizeGuard.ts through both consumers, checkBodySize() and readRequestBodyWithLimit(), plus the real image-edit route. No coverage was removed.

Reviewer Notes

This removes only OmniRoute's own media admission cap. Runtime/framework constraints and each upstream provider's native validation still apply. Non-media protections are unchanged.

@artickc
artickc requested a review from diegosouzapw as a code owner July 28, 2026 10:09
@artickc

artickc commented Jul 28, 2026

Copy link
Copy Markdown
Contributor Author

Standalone body-size floor so Media generate / edit stop dying on the 10 MB default without waiting for the full upscale feature.

The same change is also on #8791 (plus Adobe Firefly creativityLevel 0–1 wire fix for Bloom upscale).

@diegosouzapw
diegosouzapw changed the base branch from release/v3.8.49 to release/v3.8.50 July 28, 2026 18:39
@diegosouzapw

Copy link
Copy Markdown
Owner

Re-homed to release/v3.8.50: v3.8.49 entered its release freeze, so the branch now belongs to the release captain and development continues on the next cycle. Nothing is wrong with this PR — it just needed a live base. No action needed from you; CI will re-run against the new base.

@artickc
artickc force-pushed the fix/media-body-size-floor branch from 5ed365e to 959e3de Compare August 1, 2026 12:08
@artickc artickc changed the title [v3.8.50] fix(api): media body size floor for /v1/images and /v1/videos [v3.8.50] fix(api): defer media body size limits to providers Aug 1, 2026
@artickc
artickc force-pushed the fix/media-body-size-floor branch 2 times, most recently from 97ac310 to 97a993e Compare August 1, 2026 12:50
Image and video payloads vary by provider and base64 encoding adds substantial overhead. Exempt media routes from OmniRoute's global request-body cap so provider-specific validation determines whether a request is too large. Keep finite body limits for non-media routes and cover both header and streamed-body admission paths.
@artickc
artickc force-pushed the fix/media-body-size-floor branch from 97a993e to a94ba22 Compare August 1, 2026 12:52
@diegosouzapw

Copy link
Copy Markdown
Owner

Merged via local merge-train on 192.168.0.113 (32 cores) @ train tip 1efacead211f446aac3146c0599eca1ca190ac4c — log /srv/omniroute-train/.claude/worktrees/train-20260804-130726-suite.log.

Green: typecheck:core, check-complexity, check-cognitive-complexity, check-changelog-integrity, test:vitest.

test:unit: 15 failures, and every one of them reproduces identically on the clean release tip with zero PRs boarded (merge-gates §3) — no new failure was introduced by this train. Thirteen are the bare-model routing assertions left stale by #9275, which intentionally moved bare gpt-5.5/gpt-5.6-sol to codex without updating the tests that encoded the old destination; two are the trailing-period message change covered by #9392. A fix for those is in flight.

For reference, check-file-size is also a pre-existing base-red on the bare tip (src/sse/handlers/chat.ts 1846>1845, open-sse/executors/base.ts 1623>1578 — identical numbers with no PRs boarded): baseline drift for the release captain, not introduced here.

@diegosouzapw
diegosouzapw merged commit 45d375a into diegosouzapw:release/v3.8.50 Aug 4, 2026
15 of 16 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Image and video payloads vary by provider and base64 encoding adds substantial overhead. Exempt media routes from OmniRoute's global request-body cap so provider-specific validation determines whether a request is too large. Keep finite body limits for non-media routes and cover both header and streamed-body admission paths.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants