Expand description
Middleware for limiting total memory usage of concurrent HTTP request bodies.
Admission works in two stages:
- Upfront, the requestβs
Content-Length(if present) is charged to the sharedServerMemoryLimiter, preserving the configured wait/fail policy for regular requests. - While the body is streamed,
AccountedBodycharges every byte beyond the upfront reservation. This closes two gaps of a header-only reservation: HTTP/1.1 chunked requests carry noContent-Length(and would otherwise be admitted for free), and a client can understate the header while sending a much larger body.
Permits acquired while streaming are held by BodyMemoryAccounting,
which is also inserted into the request extensions so they stay alive until
the whole request is finished (extractors collect the body into owned
buffers that outlive the body stream itself).
StructsΒ§
- Accounted
Body π - A request body wrapper that charges the shared limiter for every byte
streamed beyond
pre_charged(the upfrontContent-Lengthreservation). - Body
Memory πAccounting - Holds the memory guards acquired while a request body is streamed. Shared
between the
AccountedBodywrapper, the request extensions and the middleware itself, so the permits are only released when the request (including any collected body buffers and the handler still using them) is finished. - Content
Encoded π - Marker inserted by
memory_limit_middlewarewhen the request arrives with a non-identityContent-Encodingheader. Route-localdecoded_body_accounting_middlewareuses it to account the decompressed body: only such requests expand during request decompression.
EnumsΒ§
- Charge
Outcome π
FunctionsΒ§
- decoded_
body_ πaccounting_ middleware - Route-local counterpart of
memory_limit_middlewarefor routes that installRequestDecompressionLayer: it must be layered inside the decompression layer, so the body it wraps is the decompressed stream. - limit_
exceeded_ πerror - memory_
limit_ middleware - quota_
exceeded_ πresponse - Rewrites the response of a request whose body accounting hit the quota: the failure aborts the body mid-stream, so the extractors reject the request with a generic body error (mapped to 400). Quota exhaustion must surface as 429, matching the upfront admission path, so clients can tell backpressure apart from malformed input.
Type AliasesΒ§
- Acquire
Future π