NAME

Langertha::HTTP::BoundedDecode - Bounded Content-Encoding inflate shared by the response-body decoders

VERSION

version 0.503

SYNOPSIS

use Langertha::HTTP::BoundedDecode;

my $bytes = Langertha::HTTP::BoundedDecode::decode_within(
  $response->content,                        # the raw body
  scalar $response->header('Content-Encoding'),
  $max_decoded_bytes,
  {
    too_big            => sub { croak "body exceeds $_[0]" },
    undecodable        => sub { croak "cannot decode '$_[0]'" },
    unbounded_encoding => sub { croak "cannot bound '$_[0]'" },
  },
);

DESCRIPTION

The bounded Content-Encoding inflater behind Langertha's response decoders. "decoded_content" in HTTP::Message undoes a Content-Encoding (gzip, deflate, bzip2) with no size bound, so a small compressed body can inflate to gigabytes in memory — a decompression bomb from a hostile or broken endpoint. This module inflates in bounded blocks and refuses a body once its decoded size passes $max, so the memory is capped.

It carries no error text of its own: each caller passes the three croak points, so Langertha::Content::Image (image fetches, karr k342) and Langertha::Role::HTTP (provider/metrics response bodies, karr k346) keep their own messages while sharing one inflate path. It returns the decoded bytes; charset decoding is the caller's concern.

decode_within

my $bytes = Langertha::HTTP::BoundedDecode::decode_within(
  $raw_body, $content_encoding_header, $max, \%handlers );

Undoes the Content-Encoding of $raw_body within $max decoded bytes and returns the decoded bytes. A comma-listed encoding is undone in reverse of the order it was applied. Calls $handlers->{too_big}->($max) as soon as the decoded size passes $max, $handlers->{undecodable}->($encoding) when a supported encoding is corrupt, and $handlers->{unbounded_encoding}->($encoding) for an encoding it cannot bound (anything but gzip / deflate / bzip2 and their x- aliases and identity). Each handler is expected to croak.

SEE ALSO

SUPPORT

Issues

Please report bugs and feature requests on GitHub at https://github.com/Getty/langertha/issues.

IRC

Join #langertha on irc.perl.org or message Getty directly.

CONTRIBUTING

Contributions are welcome! Please fork the repository and submit a pull request.

AUTHOR

Torsten Raudssus <getty@cpan.org>

COPYRIGHT AND LICENSE

This software is copyright (c) 2026 by Torsten Raudssus https://raudssus.de/.

This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.