From 0e9258c3005256d29267dca8c3a76e30df6f8fd1 Mon Sep 17 00:00:00 2001 From: Mert Koseoglu Date: Thu, 19 Mar 2026 21:28:17 +0300 Subject: [PATCH] fix: parseBody uses byte-accurate size check and returns 413 - Track bytes with Buffer.byteLength instead of string code units - Return 413 Payload Too Large instead of generic 500 - Custom PayloadTooLargeError class for handler discrimination Co-Authored-By: Claude Opus 4.6 (1M context) --- src/pages/api/mcp.ts | 33 +++++++++++++++++++++++++-------- 1 file changed, 25 insertions(+), 8 deletions(-) diff --git a/src/pages/api/mcp.ts b/src/pages/api/mcp.ts index 2a5dcdea..de749d1d 100644 --- a/src/pages/api/mcp.ts +++ b/src/pages/api/mcp.ts @@ -1311,15 +1311,24 @@ function createServer(options: ServerOptions = {}) { return server; } +class PayloadTooLargeError extends Error { + constructor() { + super("Body too large"); + this.name = "PayloadTooLargeError"; + } +} + async function parseBody(req: NextApiRequest): Promise { const MAX_BODY_SIZE = 1024 * 1024; // 1MB return new Promise((resolve, reject) => { let body = ""; - req.on("data", (chunk) => { + let bytesReceived = 0; + req.on("data", (chunk: Buffer | string) => { + bytesReceived += Buffer.isBuffer(chunk) ? chunk.length : Buffer.byteLength(chunk); body += chunk; - if (body.length > MAX_BODY_SIZE) { + if (bytesReceived > MAX_BODY_SIZE) { req.destroy(); - reject(new Error("Body too large")); + reject(new PayloadTooLargeError()); return; } }); @@ -1457,11 +1466,19 @@ export default async function handler(req: NextApiRequest, res: NextApiResponse) } catch (error) { console.error("MCP error:", error); if (!res.headersSent) { - res.status(500).json({ - jsonrpc: "2.0", - error: { code: -32603, message: "Internal server error" }, - id: null, - }); + if (error instanceof PayloadTooLargeError) { + res.status(413).json({ + jsonrpc: "2.0", + error: { code: -32600, message: "Payload too large. Maximum body size is 1MB." }, + id: null, + }); + } else { + res.status(500).json({ + jsonrpc: "2.0", + error: { code: -32603, message: "Internal server error" }, + id: null, + }); + } } } }