[SDK-732] Fix --next uploads over 10 MB (#14) and bump axios to 1.20.0 (#23) - #33
devtools-agent[bot] wants to merge 6 commits into
Conversation
The `--next` upload PUTs the zip with a bare axios.put, so it inherited axios's default body limit. On axios 0.x (the 0.2.1 release) that is 10 MB, and larger bundles failed with "Request body larger than maxBodyLength limit". Set maxBodyLength/maxContentLength to Infinity, as RollbarAPI already does, so the size doesn't depend on axios defaults. Also restore the axios.put stub the existing upload test leaked. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
1.15.0 already clears GHSA-wf5p-g6vw-rhxx from #23, but still has open advisories fixed in 1.15.1, 1.15.2, 1.16.0 and 1.18.0. 1.20.0 is the current release; npm audit reports no axios advisories. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
AI Agent Review LGTM (openai, openai-astra)LGTM. No blocking findings were found. LGTM — no findings. Fix: Tests: The new test Dependency: Not verified: The checkout has no Existing problems outside this diff (not findings):
|
AI Agent Review LGTM (openai, openai-astra)LGTM. No blocking findings were found. LGTM, no findings.
|
Version bumps go in their own PR. This reverts commit 06f7a4f. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
maxContentLength caps the response, not the upload, so say what each option does. Restore the axios.put stub in a finally so a failed assertion doesn't leak it into the next test. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
AI Agent Review LGTM (openai, openai-astra)LGTM. No blocking findings were found. LGTM: no issues in the changed lines.
Existing problems outside the diff (not findings, noted for follow-up):
|
Linear: SDK-732
Fixes #14. Fixes #23.
What changed
--nextuploads over 10 MB (src/sourcemaps/signed-url-uploader.js): the signed-URL PUT now passesmaxBodyLength: InfinityandmaxContentLength: Infinity, the same settingsRollbarAPIalready uses insrc/common/rollbar-api.js. (maxBodyLengthis the one that matters for the upload;maxContentLengthcaps the response and is only there to match.) Before this, the bareaxios.putfell back to axios's default limit.package.json): axios1.15.0→1.20.0, still pinned to an exact version.AGENTS.md, plusCLAUDE.mdas a symlink to it. It holds one rule, from review: don't change theversioninpackage.jsonin a PR that makes other changes; version bumps go in their own PR. So this PR no longer bumps the version. Users only get these fixes once a release is published, because 0.2.1 on npm still shipsaxios ^0.24.0, so the 0.2.2 bump needs its own PR.test/sourcemaps/signed-url-uploader.test.js): the new test PUTs an 11 MB zip to a local HTTP server. It checks that the server receives every byte and thatmaxBodyLengthisInfinity. The existing upload test left itsaxios.putstub in place for later tests. It now restores it in afinally, so the stub doesn't leak even if its assertion fails.Why
Request body larger than maxBodyLength limit, and the server receives 0 bytes. It doesn't reproduce onmaster(axios 1.15.0) or with 1.20.0, because axios v1 changed the default limit to-1, meaning unlimited. Setting the option explicitly means the upload size no longer depends on an axios default.masterby the axios v1 upgrade (Upgrade Axios to v1 #25), but it is still present in the released 0.2.1. axios 1.15.0 still has advisories fixed in 1.15.1, 1.15.2, 1.16.0 and 1.18.0. With 1.20.0,npm audit --omit=devreports no axios advisories.Validation
npm test: 37 passing, 1 pending (a skip that was already there). Before this change: 36 passing.npm run lint: clean.Overlap with #31 (SDK-731)
#31 also bumps axios to 1.20.0 and rewrites
signed-url-uploader.test.js. Whichever PR merges second will have small conflicts inpackage.json(the adjacentadm-zipline) and in that test file.npm auditstill reports one high-severity adm-zip advisory, which #31 fixes. It's out of scope here.🤖 Generated with Claude Code